How to deploy a BitLocker startup PIN on an already-encrypted Windows Pro or Enterprise OS drive

Elham Amini 0 Reputation points
2026-09-10T11:33:04.5766667+00:00

BitLocker encryption has already been deployed through Intune, and the drives on existing devices are currently encrypted.

IT now wants to enforce TPM + PIN for BitLocker on these already encrypted Windows devices.

The Endpoint Security policy configuration is already in place, and newly enrolled Intune-managed Windows devices are successfully receiving the BitLocker policy and being onboarded with TPM + PIN as expected.

However, we are looking for a scalable and user-friendly solution for existing encrypted laptops. Specifically, we would like to understand the recommended Microsoft approach for remotely enabling TPM + PIN on devices that are already encrypted, while minimizing user disruption and reducing the workload on the IT support team.

We are interested in a solution that can be deployed smoothly and, if possible, silently through Intune or another Microsoft-supported management method, rather than requiring IT administrators to manually run local command-line operations to add a PIN and modify the current TPM protector configuration on each device.

Microsoft Security | Intune | Security

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.