Laptop without bitlocker stays compliant

Pavel yannara Mirochnitchenko 11,711 Reputation points
2021-09-10T05:14:03.57+00:00

I have Compliance Policy which requires Bitlocker. I have one laptop without TPM and without bitlocker. This laptop is in the same device group with others and should be not compliant. But it has been compliant for days. When I track status of this device, I see Not Applicable for Bitlocker. What I possibly have done wrong..?

130939-image.png

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,715 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,321 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,341 Reputation points
    2021-09-10T07:03:57.847+00:00

    @Pavel yannara Mirochnitchenko Thanks for posting in our Q&A.

    For this issue, I have done the test in my lab. The result is the same as yours. It seems a known issue. It couldn't mark Windows devices with 'Not Applicable' compliance policies as non-compliant.

    I have done a lot of research. I find that someone has fed back the similar issue in the intune uservoice.
    https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/36315436-mark-windows-devices-with-not-applicable-complia

    Given this situation, it is suggested to create an online support ticket to feedback this issue more effectively. Here is the online support link and hope it helpful.
    https://learn.microsoft.com/en-us/mem/get-support

    Thanks for understanding.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Rahul Jindal [MVP] 9,141 Reputation points MVP
    2021-09-10T20:51:45.43+00:00

    The compliance state in Intune is a bit flaky. Is the device actually encrypted?


  3. Rahul Jindal [MVP] 9,141 Reputation points MVP
    2021-09-11T10:18:44.583+00:00

    Then that is the part to focus on in my opinion. Sharing some links for reference.

    intune-bitlocker-silent-and-automatic.html

    ts-bitlocker-intune-issues


  4. Pavel yannara Mirochnitchenko 11,711 Reputation points
    2021-09-13T06:15:41.943+00:00

    The half of solution was to set TPM state to be required in Compliance policies, which then turned the computer to be non-compliant. But I don't think it is enough, because you may have computers with TPM but still bitlocker is not enabled. Or you may have computers without TPM, but Bitlocker would be enabled with Password.

    0 comments No comments