BitLocker
BitLocker encrypts the drives of Windows devices. Through Intune (Endpoint security › Disk encryption) you can enable BitLocker centrally - including "silent" encryption without user interaction - and recovery keys are escrowed in Entra ID. A TPM is usually required.
Path in the Intune admin center
📍 Endpunktsicherheit › DatenträgerverschlüsselungHands-on tasks
- Windows compliance policy with BitLocker + password + minimum versionApprentice training Intune · Module 12
- Check BitLocker requirements and a security baselineApprentice training Intune · Module 13
- Find and classify the BitLocker recovery keyApprentice training Intune · Module 13
- Create a mini handover for your Intune configurationApprentice training Intune · Module 15
- FileVault - disk encryption for MacsMicrosoft Intune - Hands-on Course · Enroll macOS devices
- BitLocker policy and recovery key managementMicrosoft Intune - Hands-on Course · Module 14
- Silent BitLocker encryption - no user interactionMicrosoft Intune - Hands-on Course · Module 14
- Test the BitLocker recovery processMicrosoft Intune - Hands-on Course · Module 14
Jump straight to the matching course task (sign-in required).
On Microsoft Learn