1 min read

Intune / Windows 10 – Unable to turn on BitLocker with conflicting group policy error

Recently I came across an issue turning on BitLocker with the error

BitLocker Drive Encryption cannot be applied to this drive because there conflicting Group Policy settings for recovery options on fixed data drives.

image_thumb

Also got the error before starting the troubleshooting

You can’t create both a recovery password and a recovery key

image_thumb[1]

The policy to enable and enforce BitLocker is set on Intune/Endpoint Configuration Manager and the device has been refreshed (auto-pilot).

The device used to already have BitLocker enabled before the refresh process and re-assignment to another user.

After some troubleshooting and investigation, it was found that a registry key was the root cause of this ‘so called conflict’

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftFVE

with the below values

“FDVRecoveryPassword”=dword:00000000

“FDVRequireActiveDirectoryBackup”=dword:00000001

The FVE key is not created by Intune policy and should not be present when BitLocker is managed by Intune.

Deleting the complete FVE key solved the problem.

Windows 10 – A free file recovery tool from Microsoft

There are already thousands of file recovery tools on the market, some free, some expensive, all with different capabilities and actual results.

Read More

Azure Site Recovery – Get prepared for retirement of SCVMM disaster recovery capability

Azure Site Recovery (ASR) is the disaster recovery solution from Microsoft running on Azure to help you manage and recover from disaster for your...

Read More

Azure – You can now define the name of the resource group used by Azure Recovery Service

This is not a major new capability but still interesting as it gives you more control, you can now define the name of the resource group being used...

Read More