Windows Home device non-compliant for BitLocker in HexnodeSolved

Participant
Discussion
3 weeks ago Aug 20, 2026

One of our Windows devices is showing as non-compliant in Hexnode because BitLocker encryption is not enabled. The device is running Windows Home, which doesn’t support BitLocker.

I know BitLocker can be unchecked in the default compliance policy, but I don’t want to do that because it would affect all Windows devices, including Pro and Enterprise devices where BitLocker should remain required.

Would removing the BitLocker policy from only this Windows Home device be the right approach?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Aug 20, 2026
Marked SolutionPending Review

Hi @ed_evans,

Windows Home edition does not support BitLocker encryption. Because of this, a Windows Home device cannot satisfy a compliance rule or policy requirement that checks for BitLocker encryption.

If BitLocker compliance is enabled in a default compliance policy, Windows Home devices assigned to that policy may be marked non-compliant even though the device cannot enable BitLocker natively.

You have two practical options:

1. Disable the BitLocker compliance requirement in the default compliance policy.

  • This affects all devices assigned to that compliance policy.
  • Devices without BitLocker may still report as compliant, including Windows Pro or Enterprise devices.

2. Remove or disassociate the BitLocker-enforcing policy from only the Windows Home device or from the device group containing Windows Home devices.

  • This is the better option if you still want BitLocker enforced on supported Windows editions.
  • It allows the Windows Home device to become compliant without changing the global compliance expectation for other Windows devices.

So yes, excluding the Windows Home device from the BitLocker policy is a valid approach when BitLocker enforcement must remain active for supported Windows editions.

Regards,
Sienna Carter
Hexnode UEM

Save