BitLocker still encrypting? Why Intune marks you noncompliant
You turned on a Windows compliance policy that requires BitLocker. Half the pilot shows noncompliant within an hour. Helpdesk assumes the policy is "broken." Users are fine — their drives are just still encrypting.
This post is the short version of how we treat that gap: configure encryption, measure with grace, gate access only after the signal is trustworthy.
Companion reading:
- Conditional Access without the Monday lockout (report-only → enforce)
- Compliance before Conditional Access: an Intune enrollment → compliance runway
1. Compliance does not turn BitLocker on
| Layer | Job | Changes the device? |
|---|---|---|
| Configuration | Pushes disk encryption / Defender / update rings | Yes |
| Compliance | Evaluates "is it encrypted yet?" | No — only marks compliant / noncompliant |
| Conditional Access | Uses "compliant" to allow / MFA / block sign-ins | Blocks access, not the OS |
If you require BitLocker in compliance but never assign an encryption configuration policy, devices stay noncompliant forever. Fix config first.
2. Give encryption a grace period
BitLocker on a busy laptop is not instant. A first pilot compliance policy that requires BitLocker should usually start with a 1–3 day grace (we often use 3 days the first week), then tighten once the fleet encrypts quickly.
During grace, treat the device as "still remediating — don't panic." After grace, Intune marks noncompliant. That mark alone does not wipe, retire, or lock the device.
Pilot noncompliance actions (day one):
- Mark device noncompliant: On (after grace)
- Email / notification: optional
- Remote lock / retire / wipe: Off
"Noncompliant" often means "policy not finished applying," not "compromised."
3. Helpdesk checks when BitLocker is the failing setting
Before you escalate to CA:
- Confirm a disk-encryption configuration policy is assigned to the same pilot scope as compliance.
- On the device (elevated where needed): encryption status for the system drive (
Get-BitLockerVolume/ Company Portal sync). - In Intune: device compliance blade — which setting failed, last sync.
- Recovery key escrow in Intune (or your org's escrow process) — users will ask when something goes sideways later.
- GPO / third-party encryption conflicts that fight Intune's BitLocker policy.
Weekly read-only device/compliance CSV snapshots make "are we healthier than last Monday?" a 30-second answer. (Snapshots export state; they don't change policy or touch devices.)
4. Don't put require-compliant CA in front of a still-encrypting fleet
A Conditional Access grant of Require device to be marked as compliant will do exactly what you asked — including blocking Outlook — if devices are still mid-encryption and past grace.
Safer order:
- Configuration pushing BitLocker
- Compliance with grace, pilot only, mark-noncompliant-only
- Exit criteria (for example ≥90% compliant for several days)
- CA in report-only on the same pilot, then enforce in waves
If Insights shows a pile of "would block" for expected work, you are not ready to flip On.
5. Copy-ready starter decisions
| Decision | Starter choice |
|---|---|
| Scope | Same Intune pilot group as enrollment |
| BitLocker in compliance | Require |
| Grace | 3 days first week; tighten later |
| Destructive compliance actions | Off |
| CA pairing | Report-only first |
Write the decisions in a ticket or wiki once. Future you (and 3am you) will thank you.
Want the full runbooks?
This post is the abbreviated BitLocker / grace pattern. The Intune & M365 Admin Starter Pack ($19 during launch week; normally $29) has the full baseline-compliance playbook, enrollment hygiene, inventory snapshots, M365 admin hygiene, and break/fix cards — plus three read-only PowerShell scripts (local enrollment snapshot, Graph device snapshot, compliance policy summary). Scripts do not wipe, retire, or change policy.
👉 https://cashflow4375.gumroad.com/l/joonf
Once compliance is green and you're ready to gate access, the companion Entra ID Conditional Access Starter Pack ($29): https://cashflow4375.gumroad.com/l/nhuyrc
Not affiliated with Microsoft. Operational guidance for admins authorized to manage their tenant. Pilot first.
Top comments (0)