BitLocker Guide: Encrypt Every Laptop, Keep Every Key
GuideBitLocker is built into Windows Pro, Enterprise and Education and encrypts the whole drive, so a drive pulled from a laptop left in a taxi reads as noise without its 48-digit recovery password. This guide turns it on silently through Intune, stores each recovery key in Microsoft Entra ID before encryption starts, and walks through the morning a laptop asks for that key.
A lost laptop should cost you a laptop
Without encryption, anyone who pulls the drive out of a lost laptop can read it on another computer. No password needed, because the Windows sign-in screen only guards the front door. BitLocker encrypts the whole drive and keeps the key in the laptop's TPM chip, so the drive only unlocks inside the machine it came from, on the Windows it expects.
The catch is the recovery key. When BitLocker sees something it doesn't trust, like a firmware update or a swapped motherboard, it stops at a blue screen and asks for a 48-digit recovery password. Have it and you're working again in two minutes. Lose it and the data is gone, for you as well as the thief.
For the owner, in one line: after this, a stolen laptop is an insurance claim, not a data breach, and every recovery key sits where your IT person can find it.
What you need before you start
- Windows Pro, Enterprise, Education or Pro Education. Those are the editions Microsoft lists as supporting BitLocker management. Windows Home isn't on the list.
- Check your licence. Microsoft's table grants the BitLocker management entitlement through Windows Enterprise E3 and E5 and Education A3 and A5, and marks the Pro licence on its own as "No". Confirm what your Microsoft 365 plan includes before you lean on Intune for this.
- For silent encryption, each laptop needs: Microsoft Entra join or hybrid join, a TPM 1.2 or later, native UEFI firmware (not legacy BIOS mode), Secure Boot turned on, and a working Windows Recovery Environment.
- No other disk encryption on the drive. Silent mode skips the warning about other encryption software, and two encryption layers fighting over one drive is how laptops stop booting. Remove the old product first.
- Windows 10 reached end of support on October 14, 2025. Intune still enrolls it, but Microsoft no longer guarantees features work there. Plan this for Windows 11.
Step 1: Decide where the keys live, before anything is encrypted
Microsoft's advice is simple: laptops joined to Microsoft Entra ID store their recovery key in Entra ID, and laptops joined to on-premises Active Directory store it in AD. A standalone PC signed in with a personal Microsoft account saves its key to that account by default, which is fine for a home PC and a poor fit for a business one, because the key leaves with the employee.
The setting that matters most comes next: BitLocker can refuse to start until the key is safely backed up. Turn that on and you never meet an encrypted laptop whose only key went nowhere.
Step 2: Create the BitLocker policy in Intune
- In the Intune admin center, select Endpoint security > Disk encryption > Create Policy.
- Set Platform to Windows and Profile to BitLocker.
- Configure the settings in the table below, then assign the policy and create it.
| Setting | Value | Why |
|---|---|---|
| Require Device Encryption | Enabled | Turns BitLocker on |
| Allow Warning For Other Disk Encryption | Disabled | Required for silent mode. Only safe once no other encryption is installed |
| Allow Standard User Encryption | Enabled | Lets it run when the person signed in isn't an admin |
| Require additional authentication at startup | Enabled | Unlocks the TPM settings below |
| Configure TPM startup PIN, startup key, and key and PIN | Do not allow | Any startup prompt breaks silent mode |
| Configure TPM startup | Require TPM (or Allow TPM) | The TPM does the unlocking on its own |
| Save BitLocker recovery information to Microsoft Entra ID | Enabled | Backs up the key |
| Store recovery information in Microsoft Entra ID before enabling BitLocker | Required | No backup, no encryption |
| Client-driven recovery password rotation | Enable rotation on Microsoft Entra joined devices | A used key gets replaced (more in Step 5) |
Leave the encryption method alone unless a regulator says otherwise. The default is XTS-AES 128-bit, and Microsoft suggests 256-bit only for laptops with the CPU and drive speed to carry it.
Watch for one collision. Microsoft warns that its own security baseline for Microsoft Defender can switch on a TPM startup PIN and key, which quietly blocks silent encryption. If you've deployed that baseline, check it for conflicting BitLocker settings before you blame this policy.
Step 3: Prove it worked
On one laptop, in an elevated PowerShell window:
Get-BitLockerVolume C: | Format-List VolumeStatus, ProtectionStatus, EncryptionMethod, KeyProtector
You want ProtectionStatus: On and a KeyProtector list that includes Tpm and RecoveryPassword. The old-school check tells the same story:
manage-bde -status C:
Look at Conversion Status. Silent mode picks the type for you: Used Space Only Encrypted on laptops that support modern standby, Fully Encrypted on the rest (powercfg /a shows which kind you have). Used-space-only is fine on a new laptop. On one that held unencrypted data for years, deleted files still sit in the "free" space, readable with forensic tools until they're overwritten. For those, set Enforce drive encryption type on operating system drives to full encryption in a Settings Catalog policy before BitLocker turns on.
Then check the key actually reached Entra ID. In Intune, go to Devices > All devices, open the laptop, and under Monitor select Recovery keys. If it says No BitLocker key found for this device, the laptop is encrypted with a key nobody else holds. Fix that today: get the ID of the recovery password and push it up.
(Get-BitLockerVolume -MountPoint C).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Format-Table KeyProtectorId
BackupToAAD-BitLockerKeyProtector -MountPoint C -KeyProtectorId "{ID}"
Keep the braces in the ID. For the whole office at once, Devices > Monitor > Encryption report shows every laptop that received the policy and its encryption state.
Step 4: Get a key back on recovery day
The recovery screen shows a Key ID. That's how you pick the right key when a laptop has more than one.
- In the Intune admin center, go to Devices > All devices and open the laptop.
- Under Monitor, select Recovery keys, match the Key ID, and select Show Recovery Key.
Every reveal lands in the Entra audit log under KeyManagement, which is what you want from a key that opens a whole drive. In Entra ID, the roles that can read keys include Cloud Device Administrator, Helpdesk Administrator, Intune Administrator, Security Administrator and Security Reader, so give your technician the smallest of those that does the job.
Users can also read the key for a laptop they own, through the Company Portal, without calling anyone. If you'd rather every key request come through you, Entra has a device setting for it: Restrict non-admin users from recovering the BitLocker key(s) for their owned devices. Changing it takes at least a Privileged Role Administrator.
Step 5: Replace a key once it's been used
A recovery password that has been read out over the phone is no longer a secret. Microsoft recommends invalidating a recovery password after its use, and the rotation setting from Step 2 does it for you: on Microsoft Entra joined laptops, using the recovery password triggers a new one, which is backed up in its place.
To rotate on purpose, say after a technician leaves, open the laptop in Intune and choose the BitLocker key rotation remote action (under the ... menu if it isn't showing). It needs Windows 10 1909 or later, the Step 2 settings, and a role with Remote tasks: Rotate BitLockerKeys. The built-in Help Desk Operator and Endpoint Security Administrator roles include it.
Pause it before planned work
Firmware and BIOS updates, a replacement motherboard, clearing the TPM, and moving the drive into another computer are all on Microsoft's list of things that send a laptop into recovery. For work you can see coming, suspend protection first. The drive stays encrypted; BitLocker just steps aside for the next restart:
Suspend-BitLocker -MountPoint C -RebootCount 1
Without a reboot count, protection comes back on its own after the next restart, so you rarely need Resume-BitLocker.
Three ways to lose a key for good
- Deleting the device in Entra ID deletes its BitLocker keys. Microsoft calls it nonrecoverable. Copy the key out before you delete a laptop you might still need to open.
- Deleting the Intune record of an Entra joined laptop removes its OS drive protectors and leaves BitLocker suspended. Retire or wipe the laptop properly instead of deleting it to tidy the list.
- Entra ID holds at most 200 recovery keys per device. Hit the limit and silent encryption fails, because the backup it insists on can't happen.
Using on-premises Active Directory instead
Domain-joined laptops get the same settings through Group Policy at Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption. In the recovery settings for each drive type, select Save BitLocker recovery information to AD DS and Do not enable BitLocker until recovery information is stored in AD DS. The keys live under each computer object, AD keeps every old one until that object is deleted, and Backup-BitLockerKeyProtector pushes a missing key up the same way the Entra command does.
Sources
Checked against Microsoft Learn on 2026-10-03:
More in Windows laptops
- Microsoft Security Compliance Toolkit
- App Control for Business (formerly WDAC)
- HardeningKitty
- Windows Supply Chain Security Guide
- Windows LAPS Guide: One Admin Password Per Laptop
- BitLocker Guide: Encrypt Every Laptop, Keep Every Key