BitLocker disk encryption
BitLocker has been available since the first release of Windows Vista and gives the option to encrypt the drives attached to the endpoint. In most cases, BitLocker can work in conjunction with your endpoint that has a Trusted Platform Module (TPM) chip.
When your end users authenticate to their devices on a day-to-day basis, they will not be asked for the recovery key. But if you are moving the OS disk out of the endpoint and exchanging it for another device or getting a firmware upgrade, you might be asked for the BitLocker recovery key that is associated with your device disk to decrypt everything.
Be aware that BitLocker keys are stored on the Entra device object and not on the Intune device object. If the Entra device object is deleted, it is not possible to retrieve the recovery key again.
We covered in Chapter 7 how to configure BitLocker when doing Autopilot provisioning – it is no different from the way you need to do...