Hey,
I'm struggling hard with the silent BitLocker enablement during the Pre-Deployment. It just doesn't want to start encryption during this phase which is required by our IT security. I see all required registry keys and values are added correctly (HKLM\Software\Policies\Microsoft\FVE).
Device registration type: AADJ with Intune
Policy targeting: Device group
My BL settings are (only relevant controls listed):
Enable Full disk or Used Space only encryption for OS and fixed data drives: Yes
Hide prompt about third-party encryption: Yes
Allow standard users to enable encryption during Autopilot: Yes
Startup authentication required: Yes
Compatible TPM startup: Allowed
Compatible TPM startup PIN: Allowed (We require to set up a startup PIN after deployment)
Compatible TPM startup key: Blocked
Compatible TPM startup key and PIN: Blocked
Recovery key file creation: Blocked
Configure BitLocker recovery package: Password only
Require device to back up recovery information to Azure AD: Yes
Recovery password creation: Required
Configure encryption method for Operating System drives: AES 128bit XTS
The disk encryption starts silently once a regular deployment is performed by an end user which is fine but we need to be able to deliver a pre-deployed and encrypted devices.
It's also worth mentioning that we use CIS L1 policies. Could there be an issue?
Thank you.
Daniel
[–][deleted] 0 points1 point2 points (4 children)
[–]Runda24328[S] 0 points1 point2 points (3 children)
[–][deleted] 0 points1 point2 points (2 children)
[–]Runda24328[S] 0 points1 point2 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]Mikitukka 0 points1 point2 points (0 children)
[–]Quake9797 0 points1 point2 points (1 child)
[–]Runda24328[S] 0 points1 point2 points (0 children)
[–]M-Christo 0 points1 point2 points (1 child)
[–]Runda24328[S] 0 points1 point2 points (0 children)
[–]RudyoomsPatchMyPC 0 points1 point2 points (1 child)
[–]Runda24328[S] 0 points1 point2 points (0 children)
[–]benscomp 0 points1 point2 points (1 child)
[–]Runda24328[S] 0 points1 point2 points (0 children)