Overview
This project used Microsoft Intune to deploy BitLocker silently while protecting each device's 48-digit recovery password in Microsoft Entra ID.
Environment
Managed Windows endpoints using Microsoft Intune, Microsoft Entra ID, TPM 2.0, Secure Boot, Windows Recovery Environment, and BitLocker.
Objective
Establish repeatable endpoint encryption without losing the ability to recover a device, and prevent broader deployment until hardware and recovery prerequisites were confirmed.
Responsibilities
Configured the Intune deployment, validated prerequisites and encryption state, checked recovery-key availability, and produced change documentation supporting the implementation process.
Implementation
- Configured silent TPM-based BitLocker encryption through Intune.
- Required 48-digit recovery passwords and backup to Entra ID.
- Checked TPM 2.0, Secure Boot, and WinRE readiness before expansion.
Validation
Validation covered TPM and Secure Boot readiness, WinRE state, encryption state, and the presence of the recovery key in Entra ID before broader deployment.
Outcome
The pilot confirmed silent encryption behavior and recovery-key availability before the rollout moved beyond its initial validation stage.
Technologies
Disclosure note
Operational details have been sanitized. No recovery keys, tenant identifiers, device identifiers, or internal evidence artifacts are published.