Step reference
BitLocker
Encrypt the OS drive with a TPM protector and escrow the recovery key centrally — visible per device across every client, not scattered across each tenant.
What it does
Enables BitLocker on the OS drive with a TPM protector — silent, no PIN, no user prompt. It generates a recovery password protector and escrows the recovery key to StageReady, stored encrypted and visible per device in your dashboard.
That central escrow is the key difference from Intune BitLocker: recovery keys live in one place across all your clients, not scattered across each client's individual Entra ID. When a user is locked out, you look in one dashboard.
Options
This step has no settings — it encrypts the OS drive with strong defaults (XTS-AES-256, TPM protector) and escrows the key.
Good to know
- Requires TPM 2.0 and UEFI. It runs before OOBE as the system account, so no user login is needed. On hardware without a TPM the step can't run.
- Idempotent — if BitLocker is already on, it's a no-op.
- If encryption can't be enabled, the setup stops by default.
- Want to be sure the machine even has Secure Boot / TPM turned on first? See HP / Dell BIOS configuration and the Secure Boot check.
Part of the step catalogue.
Related
Install Windows 11
True bare-metal Windows 11 install with the right OEM driver pack injected automatically. Skips cleanly if the device already has Windows.
OOBE configuration
Auto-answer the out-of-box screens (region, keyboard, device name, EULA, optional Wi-Fi) and optionally skip the account screen so the device lands ready — no duplicate admin.
Language & region
Set the display language, keyboard layout, regional format, home location and timezone for the installed Windows and every new user. Autopilot-compatible.