Hi @ed_evans,
Windows Home edition does not support BitLocker encryption. Because of this, a Windows Home device cannot satisfy a compliance rule or policy requirement that checks for BitLocker encryption.
If BitLocker compliance is enabled in a default compliance policy, Windows Home devices assigned to that policy may be marked non-compliant even though the device cannot enable BitLocker natively.
You have two practical options:
1. Disable the BitLocker compliance requirement in the default compliance policy.
- This affects all devices assigned to that compliance policy.
- Devices without BitLocker may still report as compliant, including Windows Pro or Enterprise devices.
2. Remove or disassociate the BitLocker-enforcing policy from only the Windows Home device or from the device group containing Windows Home devices.
- This is the better option if you still want BitLocker enforced on supported Windows editions.
- It allows the Windows Home device to become compliant without changing the global compliance expectation for other Windows devices.
So yes, excluding the Windows Home device from the BitLocker policy is a valid approach when BitLocker enforcement must remain active for supported Windows editions.
Regards,
Sienna Carter
Hexnode UEM