BitLocker Not Auto-Enabling During Deployment via Configuration Manager

Suresh Kumar 60 Reputation points
2025-12-05T14:32:47.5766667+00:00

While deploying the BitLocker policy, we are encountering the below error. BitLocker is not being enabled automatically during the process.

We have verified that both TPM and Secure Boot are functioning correctly. However, the following prompt appears:

“BitLocker could not be enabled. The BitLocker encryption key cannot be obtained. Verify that the Trusted Platform Module (TPM) is enabled and ownership has been taken...”

Looking for guidance on why this occurs and how to ensure BitLocker encryption starts automatically through Configuration Manager.

User's image

Microsoft Security | Intune | Configuration Manager | Deployment
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Jindal 11,501 Reputation points
    2025-12-05T18:34:15.5866667+00:00

    What does it say in BitLocker API event log? Are you able to encrypt manually?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.