BitLocker : The encryption method of the OS volume doesn’t match the BitLocker policy

We have noticed an issue with BitLocker encryption in Windows 10/11 environment managed by Microsoft Intune. The encryption was failing on multiple devices with below errors. Upon further investigation, we identified that the issues is happening only on two HP models ( HP EliteBook 830 G6
& HP EliteBook 830 G5). The encryption was working fine on another HP models.

The BitLocker encryption was failing on multiple devices with below errors.

Error1:

The encryption method of the OS volume doesn’t match the BitLocker policy. To encrypt drives, the BitLocker policy requires either the user to sign in as an Administrator or if the device is joined to Microsoft Entra ID, the AllowStandardUserEncryption policy must be set to 1.

Error2:

The encryption method of the OS volume doesn’t match the BitLocker policy.

The devices were showing below details:

  • Encryption readiness: Not ready , Encryption status: Not encrypted
  • Encryption readiness: Ready, Encryption status: Not encrypted

Cause & Solution

As advised by Microsoft support, we have turn on the below settings in BitLocker policy. The encryption started working fine after these changes changes. However, MS could not clarify why its impacting only two hardware models.

  • Bitlocker Base Settings:
    • Warning to other disk encryption: Block
    • Allow standard users to enable encryption during Microsoft Entra join: Allow
    • Configure encryption methods: Enable

Intune BitLocker Settings

Related Posts

Subscribe to Techuisitive Newsletter

Be the first to know about our new blog posts. Get our newsletters directly in your inbox and stay up to date about Modern Desktop Management technologies & news.


Scroll to Top