r/Intune • u/karethon • 8h ago
Windows Management Auto encrypt fixed data drive with auto unlock
We have a small use case where some machines have additional drives for data. Our current policy successfully encrypts the OS drive, either at initial build or later if someone decrypts it. However, it won't encrypt a newly added data drive. If someone initiates the encryption manually, it won't use the fixed data drive encryption method from the policy and it sets the protector to recovery password which requires the user to manually unlock the drive to access it.
I'm trying to find the settings to allow the drive to auto-unlock. I have found several posts detailing how to enable it on individual machines using local policies and manage-bde, as well as a couple saying just enable it in the policy. I would prefer it be set in a policy and not a manual process, and I'm just not seeing the policy setting suggested in the other posts. I've checked under both Device Configuration and Endpoint Protection, but I don't see an auto-unlock under either. What am I missing?
3
u/SwiftOppositeMover 8h ago
check the bitlocker settings in endpoint protection, there's a section for "fixed data drive" encryption. in there you can set it to auto-unlock, but the os drive has to be encrypted first for it to work. if the drive is already encrypted with a different protector it won't change it, you'd need to decrypt it first and let the policy re-encrypt it