Can Hexnode enforce BitLocker on Windows BYOD without affecting personal files?Solved

Participant
Discussion
2 weeks ago Jul 08, 2026

I’m planning to enroll a couple of personal Windows devices into Hexnode, one running Windows 10 and another running Windows 11, and then require disk encryption on them.

Is it advisable to enforce BitLocker on BYOD devices through Hexnode? My main concern is whether encryption changes, deletes, or affects users’ personal files on the local drive. Also, if a user forgets the encryption or recovery key, can an admin retrieve it from Hexnode?

I don’t currently see an encryption policy in the portal, so I’m not sure if I need to create one first.

Replies (3)

Marked SolutionPending Review
Hexnode Expert
2 weeks ago Jul 08, 2026
Marked SolutionPending Review

Hi @sybylla,

Hexnode can enforce BitLocker encryption on enrolled Windows 10 and Windows 11 devices, including BYOD devices.

Enabling BitLocker through Hexnode does not modify, delete, or alter personal files on the local drive. BitLocker encrypts the drive and secures the data as it exists on the device.

For recovery, when BitLocker encryption is triggered through Hexnode, the BitLocker recovery key is escrowed in the Hexnode UEM portal. If a user is locked out or needs the recovery key, an admin can retrieve it from the device details page, typically from the BitLocker section or from Action History.

To enforce encryption, you need to create and deploy a BitLocker policy first. The usual path is:

  1. Go to Policies.
  2. Create a New Policy, or edit an existing policy.
  3. Navigate to Windows > Security > BitLocker.
  4. Click Configure.
  5. Configure the required BitLocker settings.
  6. Save and associate the policy with the required Windows devices or device group.

Once the policy is applied to enrolled Windows devices, Hexnode can enforce BitLocker based on the configured settings.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
2 weeks ago Jul 10, 2026
Marked SolutionPending Review

So if there is no existing encryption policy, Hexnode won’t automatically encrypt the laptops just because they are enrolled?

Marked SolutionPending Review
Hexnode Expert
2 weeks ago Jul 10, 2026
Marked SolutionPending Review

Hi @sybylla,

Device enrollment alone does not automatically enable BitLocker encryption. You need to create a BitLocker configuration under a Windows policy and deploy it to the target devices.

Without a deployed BitLocker policy, encryption would have to be enabled manually by the user or managed outside Hexnode. Using the Hexnode policy is what allows admins to enforce the configuration and access the escrowed recovery key from the portal.

Regards,
Sienna Carter
Hexnode UEM

Save