Step reference

BitLocker

Encrypt the OS drive with a TPM protector and escrow the recovery key centrally — visible per device across every client, not scattered across each tenant.

1 min readUpdated Jul 21, 2026

What it does

Enables BitLocker on the OS drive with a TPM protector — silent, no PIN, no user prompt. It generates a recovery password protector and escrows the recovery key to StageReady, stored encrypted and visible per device in your dashboard.

That central escrow is the key difference from Intune BitLocker: recovery keys live in one place across all your clients, not scattered across each client's individual Entra ID. When a user is locked out, you look in one dashboard.

Options

This step has no settings — it encrypts the OS drive with strong defaults (XTS-AES-256, TPM protector) and escrows the key.

Good to know

  • Requires TPM 2.0 and UEFI. It runs before OOBE as the system account, so no user login is needed. On hardware without a TPM the step can't run.
  • Idempotent — if BitLocker is already on, it's a no-op.
  • If encryption can't be enabled, the setup stops by default.
  • Want to be sure the machine even has Secure Boot / TPM turned on first? See HP / Dell BIOS configuration and the Secure Boot check.

Part of the step catalogue.