DEV Community

AdminPackStudio
AdminPackStudio

Posted on

BitLocker still encrypting? Why Intune marks you noncompliant — and how grace periods save Monday

BitLocker still encrypting? Why Intune marks you noncompliant

You turned on a Windows compliance policy that requires BitLocker. Half the pilot shows noncompliant within an hour. Helpdesk assumes the policy is "broken." Users are fine — their drives are just still encrypting.

This post is the short version of how we treat that gap: configure encryption, measure with grace, gate access only after the signal is trustworthy.

Companion reading:

1. Compliance does not turn BitLocker on

Layer Job Changes the device?
Configuration Pushes disk encryption / Defender / update rings Yes
Compliance Evaluates "is it encrypted yet?" No — only marks compliant / noncompliant
Conditional Access Uses "compliant" to allow / MFA / block sign-ins Blocks access, not the OS

If you require BitLocker in compliance but never assign an encryption configuration policy, devices stay noncompliant forever. Fix config first.

2. Give encryption a grace period

BitLocker on a busy laptop is not instant. A first pilot compliance policy that requires BitLocker should usually start with a 1–3 day grace (we often use 3 days the first week), then tighten once the fleet encrypts quickly.

During grace, treat the device as "still remediating — don't panic." After grace, Intune marks noncompliant. That mark alone does not wipe, retire, or lock the device.

Pilot noncompliance actions (day one):

  • Mark device noncompliant: On (after grace)
  • Email / notification: optional
  • Remote lock / retire / wipe: Off

"Noncompliant" often means "policy not finished applying," not "compromised."

3. Helpdesk checks when BitLocker is the failing setting

Before you escalate to CA:

  1. Confirm a disk-encryption configuration policy is assigned to the same pilot scope as compliance.
  2. On the device (elevated where needed): encryption status for the system drive (Get-BitLockerVolume / Company Portal sync).
  3. In Intune: device compliance blade — which setting failed, last sync.
  4. Recovery key escrow in Intune (or your org's escrow process) — users will ask when something goes sideways later.
  5. GPO / third-party encryption conflicts that fight Intune's BitLocker policy.

Weekly read-only device/compliance CSV snapshots make "are we healthier than last Monday?" a 30-second answer. (Snapshots export state; they don't change policy or touch devices.)

4. Don't put require-compliant CA in front of a still-encrypting fleet

A Conditional Access grant of Require device to be marked as compliant will do exactly what you asked — including blocking Outlook — if devices are still mid-encryption and past grace.

Safer order:

  1. Configuration pushing BitLocker
  2. Compliance with grace, pilot only, mark-noncompliant-only
  3. Exit criteria (for example ≥90% compliant for several days)
  4. CA in report-only on the same pilot, then enforce in waves

If Insights shows a pile of "would block" for expected work, you are not ready to flip On.

5. Copy-ready starter decisions

Decision Starter choice
Scope Same Intune pilot group as enrollment
BitLocker in compliance Require
Grace 3 days first week; tighten later
Destructive compliance actions Off
CA pairing Report-only first

Write the decisions in a ticket or wiki once. Future you (and 3am you) will thank you.

Want the full runbooks?

This post is the abbreviated BitLocker / grace pattern. The Intune & M365 Admin Starter Pack ($19 during launch week; normally $29) has the full baseline-compliance playbook, enrollment hygiene, inventory snapshots, M365 admin hygiene, and break/fix cards — plus three read-only PowerShell scripts (local enrollment snapshot, Graph device snapshot, compliance policy summary). Scripts do not wipe, retire, or change policy.

👉 https://cashflow4375.gumroad.com/l/joonf

Once compliance is green and you're ready to gate access, the companion Entra ID Conditional Access Starter Pack ($29): https://cashflow4375.gumroad.com/l/nhuyrc


Not affiliated with Microsoft. Operational guidance for admins authorized to manage their tenant. Pilot first.

Top comments (0)