scloud by Florian Salzmann
ende

BitLocker: Cloud Only vs. Hybrid

Cloud-only BitLocker policies, configured via Intune’s Endpoint security > Disk encryption, work reliably on Azure AD-joined devices but often fail to activate on hybrid-joined ones. For hybrid environments, use the classic Endpoint protection Configuration profile instead - and never assign both policy types to the same device.

For me it’s without question that BitLocker belongs on every device. Whether with a PIN or not depends a bit on the scenario.

For some time now, Endpoint Manager offers the “Endpoint security” tab, where you can manage security settings like Defender settings, Firewall and BitLocker.

In several hybrid environments I noticed that many devices have problems with the new configuration and don’t activate BitLocker. Because of this, I started to only use BitLocker via “Endpoint security” in environments where exclusively cloud only devices are used. For hybrid environments (starting with an Azure AD Hybrid Join device) I still use the classic “Endpoint protection” “Configuration profile”.

What’s the Difference Between Cloud Only and Hybrid BitLocker?

Cloud OnlyHybrid
Where to configureEndpoint security > Disk encryptionDevices > Windows > Configuration profiles
Policy name used here”WIN BitLocker""WIN BitLocker (Classic)“
Best forAzure AD (Entra ID) joined, cloud-only devicesAzure AD Hybrid Join devices - Autopilot hybrid, AD + Hybrid Sync, or GPO enrollment
Common issueNone when scoped correctlyActivation failures if the cloud-only profile is also assigned
Key ruleUse only on cloud-only devicesAssign only one BitLocker profile per device - never both

How Do You Configure BitLocker for Cloud-Only Devices?

  • I create the policy under Endpoint security > Disk encryption > Create Policy

Creating a BitLocker disk encryption policy under Endpoint security in Intune

  • As a name I choose “WIN BitLocker” or, if the customer has special naming conventions, one according to the concept. With the settings below I’ve had good experience over the past year:

BitLocker cloud-only policy settings in Intune Endpoint security

How Do You Configure BitLocker for Hybrid Devices?

  • I create the policy under Devices > Windows > Configuration profiles > Create profile

Creating a BitLocker configuration profile for hybrid devices in Intune

  • As a name I choose “WIN BitLocker (Classic)” or, if the customer has special naming conventions, one according to the concept. With the settings below, the configuration also works with hybrid devices deployed via Autopilot as well as those enrolled via AD, Hybrid Sync and GPO:

BitLocker hybrid configuration profile settings in Intune

How Do You Verify BitLocker Encryption Status?

Don’t just trust that the policy applied - check the actual encryption state. In the Intune admin center, “Devices > Monitor > Encryption report” shows the BitLocker status per device and flags devices stuck in “Encryption in progress” for longer than expected. On the device itself, manage-bde -status gives you the definitive answer, including whether protection is actually “On” and which encryption method is in use.

Why Do Devices Get Stuck Without Activating BitLocker?

The most common cause I run into is a missing or not-yet-escrowed TPM protector - if the recovery key hasn’t been backed up to Entra ID yet (check under the device’s “BitLocker keys” blade), Intune won’t consider the device compliant even if encryption technically ran. The second most common cause is a policy conflict: having both the “Endpoint security” disk encryption profile and the classic “Configuration profile” assigned to the same device produces unpredictable results - assign only one per device, matching the cloud-only vs. hybrid split described above.

Related posts

Hybrid Cloud Trust Deployment
Microsoft Intune

Windows Hello for Business - Cloud Kerberos Trust - Hybrid

Ensure successful authentication and SSO via Kerberos to local resources with the Windows Hello for Business Cloud Trust.

Windows Autopilot Intune
Intune Starter Series

Windows Autopilot: Overview and Setup

Microsoft Intune - Unlock the full potential of Microsoft Intune with our comprehensive Starter Series. Explore in-depth guides and tips for seamless device management and security.

Defender Web Filter
Defender for Business

Defender for Endpoint - Web Filter

With Defender for Endpoint and Defender for Business, implement a web filter regardless of location and monitor it centrally.