Intune BitLocker Policy Deployment and Troubleshooting
Background This lab was completed as part of my preparation for the MD-102 Endpoint Administrator exam. I used a personal Microsoft 365 Business Premium lab tenant to practise endpoint security management with Microsoft Intune. Objective Create a Security group Add a Windows device to the group Create a BitLocker disk encryption policy Assign the policy to a device group Sync the device from Intune Check the policy deployment result Identify why the policy did not apply successfully Lab Environment Item Details Tenant type Microsoft 365 Business Premium lab tenant Admin center Microsoft Intune admin center Device name LAPTOP-D42OPL9H Windows edition Windows 11 Home Chinese edition Windows version Windows 11 25H2, OS build 26200.8655 Device join type Microsoft Entra registered / MDM-only enrolled device Enrollment method Manual MDM enrollment License Microsoft 365 Business Premium Device group LAB-Windows-Devices Group type Security Membership type Assigned Policy name LAB-BitLocker-Baseline Policy type Endpoint security > Disk encryption > BitLocker Policy platform Windows Assignment target MDM Device compliance status Compliant Last device check-in time 6/15/2026, 12:53:21 PM Steps Step 1: Create a device Security group I created a new Security group named LAB-Windows-Devices in the Microsoft Intune admin center. The group used the Assigned membership type, which means devices must be added manually. ...