Require Bitlocker with PIN

RASH MAAR 421 Reputation points
2020-10-21T21:52:09.617+00:00

Hi,

Is there a way to force users to activate Bitlocker?
I created a profile and set Require under Encrypt devices,
And it only gives a one-time alert to the user and does not require him to activate the Bitlocker.
And I see the article here to set up the encryption silently but it will be without PIN request at computer startup.
https://msendpointmgr.com/2019/10/31/silently-enable-bitlocker-for-hybrid-azure-ad-joined-devices-using-windows-autopilot/

Is there a way to run Bitlocker silently with randomly PIN or PIN written in the script and the user must change it after that??

Thanks
Rash

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,753 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,716 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,324 questions
{count} votes

3 answers

Sort by: Most helpful
  1. CiciWu-MSFT 1,201 Reputation points
    2020-10-22T03:00:09.423+00:00

    Currently it doesn’t seem to support force Bitlocker with PIN by Intune. The BitLocker policy must not require use of a startup PIN or startup key. When a TPM startup PIN or startup key is required, BitLocker can't silently enable and requires interaction from the end user.
    Reference: https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#silently-enable-bitlocker-on-devices

    Some end users have already post such request in Intune UserVoice, I think you can vote the following ticket to address this issue. Many features of our current products are designed and upgraded based on customer feedback. We strive to capture any negative reviews in order to ensure that we are continuously improving our products to meet our customers' needs. With your efforts, we are committed to improving our products. Here is the link:
    https://microsoftintune.uservoice.com/forums/291681-ideas?query=Bitlocker%20with%20PIN

    1 person found this answer helpful.
    0 comments No comments

  2. MTG 1,196 Reputation points
    2020-10-22T06:56:26.537+00:00

    See my article at expert exchange: https://www.experts-exchange.com/articles/33771/We-have-bitlocker-so-we-need-MBAM-too.html?preview=hG26jVC1xow%3D
    It provides a script to turn on BL with PIN automatically using task scheduler.

    0 comments No comments

  3. Oliver Kieselbach 241 Reputation points MVP
    2020-11-14T11:28:45.633+00:00

    Hi @RASH MAAR ,

    if you are looking for a solution with Intune and AADJ devices I do have a blog post about it here:

    How to enable Pre-Boot BitLocker startup PIN on Windows with Intune
    https://oliverkieselbach.com/2019/08/02/how-to-enable-pre-boot-bitlocker-startup-pin-on-windows-with-intune/

    best,

    ---
    Oliver Kieselbach | Twitter | Blog
    Mark useful answers by clicking "Accept Answer", many thanks!

    0 comments No comments