Bitlocker Key Rotation Failed Intune, But the issue is there is no recovery key backed up in Entra ID or Intune.


 

Bitlocker Key Rotation Failed Intune, This helps reduce the risk of unauthorized access if a recovery key has been used or potentially exposed. Jun 23, 2021 · The error I'm getting is Client-driven recovery password rotation Fails with -2016281112 (Remediation failed) error code 0x87d1fde8 Event log on the endpoint shows that configure recovery password rotation URI request is not supported: Oct 7, 2023 · Intune- Bitlocker Recovery key Rotation + Non Compatible TPM Windows 10, version 1909 introduced new BitLocker Configuration Service Provider (CSP) settings to configure recovery password rotation. Encryption worked fine and Drive is fully encrypted. I have applied this to my testing group. For more details about Migration from StandAlone MBAM, see Microsoft Docs For more information on BitLocker Management with Configuration Manager, see Microsoft Docs. Apr 15, 2026 · Tip Intune provides a built-in encryption report that presents details about the encryption status of devices across all your managed devices. While it was previously working fine, for the past two weeks, devices assigned to the Bitlocker policy are encrypting successfully, but the recovery keys are not syncing to Intune/Entra. After Intune encrypts a Windows device with BitLocker, you can view and manage BitLocker recovery keys when you view the encryption report. Apr 21, 2026 · The BitLocker key rotation action in Microsoft Intune lets IT admins remotely refresh the recovery key for the operating system drive on BitLocker-encrypted Windows devices. Below is a screenshot of the settings I used. Jul 15, 2021 · Hello Community! This is my first posting looking for answers. Nov 20, 2019 · At Ignite 2019 Microsoft announced BitLocker key rotation for Intune managed Windows 10 devices. . After the policy pushes to the device, it This script connects to Intune via Graph API and rotates the BitLocker keys for all managed Windows devices. In doing some testing, I have created a configuration profile using the settings catalog. May 31, 2023 · When a device processes the MECM BitLocker Management policy, it will automatically do a key rotation and upload the new key to MECM. Client-driven recovery password rotation - Key rotation enabled for Azure AD and Hybrid-joined devices As an additional bit of info - I attempted the Recovery Key Rotation from Intune Console, which did trigger on my device. May 21, 2021 · If I have a Bitlocker policy in Intune and the recovery password rotation is turned on for both Azure AD and Hybrid-Joined devices. I'm pretty new to Intune and Endpoint Manager. Jun 5, 2026 · Summary: This article guides you through key concepts related to BitLocker key rotation, including how it works, the Group Policy settings involved, how to use PowerShell to manage keys, and how to automate the process using tools like Intune. Is it possible to rotate bitlocker keys via Intune with this setup or do we have to move to bitlocker being managed by intune configuration policy. Apr 8, 2024 · I have deployed Bitlocker Encryption an Intune Windows Encryption configuration profile. If I turn ON the setting "Store… Jul 29, 2025 · Self-recovery The BitLocker recovery password and recovery key for an operating system drive or a fixed data drive can be saved to one or more USB devices, printed, saved to Microsoft Entra ID or AD DS. When you want to make sure the recovery keys are uploaded, please configure these settings. But the issue is there is no recovery key backed up in Entra ID or Intune. I'm trying to disable the News and Interests from the taskbar. Key rotation is especially useful in environments where devices are frequently serviced, reassigned, or exposed to Dec 2, 2024 · Hello All, We’ve configured Bitlocker settings in Intune using a device configuration profile in a hybrid environment. Key rotation is especially useful in environments where devices are frequently serviced, reassigned, or exposed to However, if I backup keys manually from the client immediately after with manage-bde -protectors -adbackup c: -id {bla} as system via psexec to simulate the task above current keys are backedup succesfuly and event viewer reports event 784 ("BitLocker Drive Encryption recovery information was backed up successfully to Active Directory Domain Jan 21, 2025 · Configuring BitLocker encryption settings on Windows devices to allow for recovery key rotation initiated from Intune console. Dec 16, 2024 · Currently gpo policy controls bitlocker and keys write to ad ds but keys are visible in intune. Now let say a workstation was triggered into recovery mode, and the user was able to grab the key from… Apr 15, 2026 · Use Microsoft Intune policy to manage BitLocker encryption on Windows devices, including silent encryption and Personal Data Encryption. Feb 4, 2021 · You can deploy Bitlocker in Intune by creating a new device configuration profile or an Endpoint security Profile. The BitLocker key rotation action in Microsoft Intune lets IT admins remotely refresh the recovery key for the operating system drive on BitLocker-encrypted Windows devices. It is a long awaited feature and closes the feature gaps in the cloud managed BitLocker solution. Key rotation helps improve device security by rotating the password once it has been used for recovery, preventing reuse of the same password. lcz7l, cru, udr3okg, nwmu5e, kyho, kwz8yxoq, 3l0sxw, rta2, zah, m3j,