Intune - BitLocker - Azure AD Joined - Script ?

Julien bastin 21 Reputation points
2021-03-26T14:39:01.713+00:00

Hello everyone,

I'm newbie with Microsoft Intune, and relatively new in my job.

For a client I have to migrate him from AirWatch to Intune, but I have a problem with encryption, my client would like to activate encryption silently on his devices without the pop-up. I explained him that's possible, but only if the devices are Azure AD Joined, I showed him how to do it, but the problem is : For a device to be able to join via Azure AD, it can't be joined previously via AD (On-premise), so he disconnected from Active Directory (Settings > Accounts > Access Work or School) and Disconnect button.

But when he did the manipulation, of course he couldn't access to network shared, etc.. Provided by his previous AD (On-Premise).

So I'm looking for a solution, to allow BitLocker to encrypt the devices silently and to get back the Keys to Azure AD or Intune, I was thinking about script ? To use with Intune.

Do you have a better solution ?

PS : Another problem is that if the user is joined via Azure AD and that it connects with his account : johndoe@mycompany.com some applications will not working, because my client use "special" username like SP-01 to works with some applications.

Thank you in advance, and sorry for my bad english.

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
159 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,302 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 42,631 Reputation points Microsoft Vendor
    2021-03-29T01:53:02.517+00:00

    @Julien bastin ,Thanks for posting in our Q&A. Based on our official article, to manage Bitlocker, the devices can be Azure AD joined or Hybrid Azure AD joined.
    82085-image.png
    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#manage-bitlocker

    From your description, the device we want to manage Bitlocker is joined to on premise AD. For these devices Hybrid Azure Ad join may be more suitable. We cans see more details for Hybrid Azure AD Joined devices in the following article:
    https://learn.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-join-hybrid

    To configure Hybrid Azure AD joined, we can choose one of the following methods: according to our domain type
    https://learn.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains
    https://learn.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-federated-domains

    For your question, I think when we choose Hybrid Azure AD joined, the user can still use their on premise domain account to access application.

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful