SCCM - BitLocker Compliant Machines showing as Non Compliant

Roger Hendrikse 246 Reputation points
2021-03-03T12:08:49.177+00:00

We are using SCCM 2010 to manage our machines, including applying a BitLocker Policy that enables BitLocker encryption. We have set OS drive encryption to require TPM chip, and have set Fixed Drive encryption to auto unlock.

The waay i understand it, the settings for Fixed Drive apply to all internal fixed drives that are NOT the OS drive.

For some reason, 90% of our devices are showing up as non compliant in the BitLocker Compliance Dashboard report, even though they ARE BitLocker encrypted. If I go to these devices, they all show the same as below

73765-noncompliant.jpg

As you can see, the Operating system drive is showing as compliant, but it shows as non compliant for Fixed Data Drive Compliance. I do not see why this would show as such, when the computer only has one drive (and this is the OS drive, which is compliant). For some machines (about 10%) the machines show as compliant for both Operating System AND Fixed Data Drive.

Please can someone explain why this is happening and how to remedy it, because at the moment, the BitLocker Compliance reports are useless

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,768 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Roger Hendrikse 246 Reputation points
    2021-03-18T10:04:55.25+00:00

    So the 2010 HFRU seems to have resolved the issue - https://support.microsoft.com/en-us/topic/update-rollup-for-microsoft-endpoint-configuration-manager-current-branch-version-2010-403fa677-e418-e39d-6eb6-f279ea991a95

    Installed this and after machiens updated their client, they seem to be showing as properly compliant now :-)

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Fiona Yan-MSFT 2,311 Reputation points
    2021-03-04T08:52:18.367+00:00

    @Roger Hendrikse

    Thank you for posting in Microsoft Q&A forum.

    Maybe we could check the status of the bitlocker policy on client side like the image shown below:
    74245-image.png

    Have a good day!


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.