I’m testing BitLocker deployment for Windows devices through Hexnode UEM and expected encryption to start automatically without user action.
The BitLocker policy has OS and fixed drive encryption required, TPM startup enabled, startup PIN/key disabled, recovery options enabled, and recovery password escrow configured. The device has TPM present, ready, and enabled.
Instead of encrypting silently, Windows shows an “Encryption needed” notification. When the user clicks it, Windows opens Device Encryption Settings and asks the user to select “Turn on”. In some cases, it also asks the user to sign in with a Microsoft account.
What is the recommended Hexnode workflow to enable BitLocker without relying on the user to click “Turn on”? Should the BitLocker policy alone start encryption, or do I need to trigger something else from the device actions?