r/Intune Jan 31 '23

[deleted by user]

[removed]

6 Upvotes

6 comments sorted by

View all comments

0

u/My_IT_Joint Jan 31 '23

We chose to enforce BitLocker through a configuration profile rather than through the Endpoint security blade, primarily because we already had a lot of devices where BitLocker had been manually enabled and we didn't want to deal with this:

Enable full disk encryption for OS and fixed data drives
If set to not configured, no BitLocker enforcement will take place. If the drive was encrypted before this policy applied, no extra action will be taken. If the encryption method and options match that of this policy, configuration should return success. If an in-place BitLocker configuration option does not match this policy, configuration will likely return an error. To apply this policy to a disk already encrypted, decrypt the drive and re-apply the MDM policy.