Managing and enforcing security policies for devices and apps to protect organizational data through Intune
How to deploy a BitLocker startup PIN on an already-encrypted Windows Pro or Enterprise OS drive
BitLocker encryption has already been deployed through Intune, and the drives on existing devices are currently encrypted.
IT now wants to enforce TPM + PIN for BitLocker on these already encrypted Windows devices.
The Endpoint Security policy configuration is already in place, and newly enrolled Intune-managed Windows devices are successfully receiving the BitLocker policy and being onboarded with TPM + PIN as expected.
However, we are looking for a scalable and user-friendly solution for existing encrypted laptops. Specifically, we would like to understand the recommended Microsoft approach for remotely enabling TPM + PIN on devices that are already encrypted, while minimizing user disruption and reducing the workload on the IT support team.
We are interested in a solution that can be deployed smoothly and, if possible, silently through Intune or another Microsoft-supported management method, rather than requiring IT administrators to manually run local command-line operations to add a PIN and modify the current TPM protector configuration on each device.