Skip to main content

How to Deploy BitLocker Encryption Across an Organisation

A complete guide to deploying BitLocker drive encryption across your business using Intune, Group Policy, or PowerShell — including Microsoft Entra ID key backup.

5 min readUpdated March 29, 2026

Overviewsection

BitLocker is the built-in full-disk encryption feature in Windows Pro, Enterprise, and Education editions. Deploying it across your organisation protects data on lost or stolen laptops and is required by most compliance frameworks including CMMC, NIST 800-171, and Cyber Essentials.

This guide covers three deployment methods and how to ensure recovery keys are safely backed up to Microsoft Entra ID or on-premises Active Directory.

Prerequisitessection

  • Windows 11 Pro, Enterprise, or Education (BitLocker is not available on Home)
  • TPM 2.0 chip (standard on all modern hardware)
  • For Intune: Devices enrolled in Microsoft Intune
  • For Group Policy: Active Directory domain-joined devices
  • Admin access to configure policies

Step 1 — Create an endpoint security policysection

  1. Go to the Microsoft Intune admin centre (intune.microsoft.com) > Endpoint security > Disk encryption
  2. Click Create Policy
  3. Select Windows 10 and later > BitLocker

Step 2 — Configure BitLocker settingssection

SettingRecommended Value
Require device encryptionYes
BitLocker OS drive encryption methodXTS-AES 256
BitLocker fixed drive encryption methodXTS-AES 256
Startup authenticationTPM only (or TPM + PIN for high-security)
Recovery key rotationEnabled
Store recovery key in Microsoft Entra IDYes
Hide recovery key prompt from usersYes

Step 3 — Assign the policysection

Assign to a device group. Start with a pilot group before rolling out to all devices.

Step 4 — Monitor encryption statussection

Go to Devices > Monitor > Encryption report to track which devices have been encrypted and which are pending.

Tip

Intune silently encrypts the OS drive without user interaction when the device has a TPM and meets all prerequisites. The user does not need to do anything.

Method 2: Group Policy (On-Premises AD)section

Step 1 — Configure AD to store recovery keyssection

Before enabling BitLocker, configure AD to accept recovery key backups:

  1. Extend the AD schema for BitLocker (if not already done):
powershell
# Run on a Domain Controller
Import-Module ActiveDirectory
# Verify BitLocker schema extensions exist
Get-ADObject -SearchBase (Get-ADRootDSE).schemaNamingContext -Filter {Name -eq "ms-FVE-RecoveryPassword"}
  1. Set permissions on the OU so computer objects can write recovery keys

Step 2 — Create a Group Policysection

Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives

Configure these settings:

SettingValue
Require additional authentication at startupEnabled, Allow TPM, do not allow startup key
Choose drive encryption method (Windows 10 1511+)XTS-AES 256-bit
Choose how BitLocker-protected OS drives can be recoveredEnabled, save to AD DS, do not enable BitLocker until key is stored

Step 3 — Apply and verifysection

powershell
# Force group policy update
gpupdate /force

# Check BitLocker status
manage-bde -status C:

Method 3: PowerShell (Scripted Deployment)section

For quick deployment or environments without Intune or GPO:

powershell
# Enable BitLocker with TPM protector and back up to Microsoft Entra ID
Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -TpmProtector -SkipHardwareTest

# Add a recovery password protector
$recoveryPassword = Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector

# Back up the recovery key to Microsoft Entra ID
BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $recoveryPassword.KeyProtector[-1].KeyProtectorId
Warning

Always verify the recovery key has been backed up before considering the deployment complete. A BitLocker-encrypted drive without an accessible recovery key means permanent data loss if the TPM fails.

Recovery Key Managementsection

Finding keys in Microsoft Entra IDsection

  1. Go to the Microsoft Entra admin center (entra.microsoft.com) > Devices > All devices > search for the device
  2. Click the device > BitLocker keys
  3. The recovery key ID and key are displayed

Finding keys via PowerShellsection

powershell
# For Microsoft Entra ID (requires Microsoft Graph module)
Get-MgInformationProtectionBitlockerRecoveryKey -Filter "deviceId eq 'DEVICE-ID'"

# For on-premises AD
Get-ADObject -Filter {objectclass -eq 'msFVE-RecoveryInformation'} -SearchBase "OU=Workstations,DC=corp,DC=example,DC=com" -Properties msFVE-RecoveryPassword

Key rotationsection

After a recovery key is used, rotate it:

  • Intune: Recovery key rotation happens automatically if configured in the policy
  • Manual: Run manage-bde -protectors -delete C: -Type RecoveryPassword then add a new one

Compliance Reportingsection

For compliance audits, generate a report of encryption status across all devices:

powershell
# Intune — export from the admin centre
# On-premises — scan via PowerShell
$computers = Get-ADComputer -Filter * -SearchBase "OU=Workstations,DC=corp,DC=example,DC=com"
foreach ($pc in $computers) {
    $status = Invoke-Command -ComputerName $pc.Name -ScriptBlock {
        (Get-BitLockerVolume -MountPoint "C:").VolumeStatus
    } -ErrorAction SilentlyContinue
    [PSCustomObject]@{
        Computer = $pc.Name
        Status   = if ($status) { $status } else { "Unreachable" }
    }
} | Export-Csv -Path ".\BitLockerStatus.csv" -NoTypeInformation

Troubleshootingsection

IssueCauseFix
"BitLocker cannot use TPM"TPM not enabled in BIOSEnter BIOS and enable TPM / Intel PTT
Encryption stuck at 0%Disk errors preventing encryptionRun chkdsk C: /r and retry
Recovery key not in Microsoft Entra IDBackup step failed silentlyRun BackupToAAD-BitLockerKeyProtector manually
User prompted for recovery key at bootTPM firmware update or BIOS changeEnter the recovery key, then suspend and resume BitLocker
"This device can't use a TPM" on IntunePolicy requires TPM but device lacks itAllow password-based protector as fallback or exclude device

Next Stepssection

  • Combine BitLocker with Conditional Access to block unencrypted devices from accessing company data
  • Set up BitLocker recovery key rotation in Intune
  • Consider deploying Windows LAPS (built into Windows 11 23H2 and later) to manage local administrator passwords alongside BitLocker
  • Document recovery key access procedures for your helpdesk team

Need help with a device rollout?section

For ongoing device administration, see our managed IT support plans. If you are troubleshooting one device, on-demand remote support is the relevant starting point.

BitLockerEncryptionWindows 11IntuneGroup Policy

Was this article helpful?