Other Intune-related topics, including unsupported scenarios and platform-specific behaviors
For the latest enterprise view, use the Microsoft Intune encryption report as the central reporting view for managed devices. It is described as a centralized location to view a device’s encryption status, and it is the recommended starting point for troubleshooting and identifying BitLocker encryption failures across managed devices.
In Intune, the report is available in the admin center under:
- Devices > Manage devices > Configuration > Monitor > Device encryption status
What the Intune reporting view provides:
- Encryption status across managed devices
- TPM status for Windows devices
- Identification of devices that are encrypted, ready to be encrypted, or not ready
- Status details that help isolate common BitLocker failure categories
The documented BitLocker flow in Intune is:
- An administrator configures a BitLocker policy in Intune.
- The policy is saved in the Intune service.
- The Windows MDM client syncs with Intune and processes the BitLocker policy.
- The BitLocker MDM policy refresh scheduled task runs on the device.
- BitLocker encryption is initiated on the drives.
That means the Intune UI is not a direct live device query. It reflects device state reported through the Intune management and MDM sync process, and the guidance for client-side investigation starts with a manual device sync when current report data is insufficient.
For a full enterprise risk view related to BitLocker encryption, use this approach:
- In Intune, open Device encryption status to get the centralized fleet view.
- Review devices marked as:
- Not encrypted
- Ready but not encrypted
- Not ready or Not applicable for encryption readiness
- Use the device status details in the encryption report to separate common risk categories:
- Device does not meet BitLocker prerequisites
- BitLocker policy misconfiguration or GPO conflict
- Device is already encrypted but the encryption method does not match policy
- For devices where the report does not provide enough detail, access the device and:
- Manually sync it from Settings > Accounts > Access work or school > account > Info > Sync
- Collect the MDM Diagnostic Report from
C:\Users\Public\Documents\MDMDiagnostics - Use that report to confirm OS support, policy targeting, and which BitLocker CSP settings were received
- If silent encryption is expected, pay special attention to TPM readiness because devices that are Not ready or Not applicable often indicate TPM is not ready for BitLocker.
If the goal is “source of truth for latest status,” the supported answer is:
- For enterprise-wide monitoring and risk visibility: the Intune encryption report is the authoritative centralized view.
- For the most detailed per-device investigation when report data is incomplete: the device-side diagnostics and sync state are required.