Hi @sybylla,
Hexnode can enforce BitLocker encryption on enrolled Windows 10 and Windows 11 devices, including BYOD devices.
Enabling BitLocker through Hexnode does not modify, delete, or alter personal files on the local drive. BitLocker encrypts the drive and secures the data as it exists on the device.
For recovery, when BitLocker encryption is triggered through Hexnode, the BitLocker recovery key is escrowed in the Hexnode UEM portal. If a user is locked out or needs the recovery key, an admin can retrieve it from the device details page, typically from the BitLocker section or from Action History.
To enforce encryption, you need to create and deploy a BitLocker policy first. The usual path is:
- Go to Policies.
- Create a New Policy, or edit an existing policy.
- Navigate to Windows > Security > BitLocker.
- Click Configure.
- Configure the required BitLocker settings.
- Save and associate the policy with the required Windows devices or device group.
Once the policy is applied to enrolled Windows devices, Hexnode can enforce BitLocker based on the configured settings.
Regards,
Sienna Carter
Hexnode UEM