Information
This setting allows Admin to disable all UI (notification for encryption and warning prompt for other disk encryption) and turn on encryption on the user machines silently.
When you disable the warning prompt, the OS drive's recovery key will back up to the user's Microsoft Entra account. When you allow the warning prompt, the user who receives the prompt can select where to back up the OS drive's recovery key.
The endpoint for a fixed data drive's backup is chosen in the following order:
- The user's Windows Server Active Directory Domain Services account.
- The user's Microsoft Entra account.
- The user's personal OneDrive (MDM/MAM only).
Encryption will wait until one of these three locations backs up successfully.
The recommended state for this setting is: Disabled
Note: Starting in Windows 10, version 1803, the value 0 can only be set for Microsoft Entra joined devices. Windows will attempt to silently enable BitLocker for value 0.
Silent encryption enables BitLocker to encrypt data without prompting the user, ensuring the encryption process is uninterrupted.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :
Bitlocker\Allow Warning For Other Disk Encryption
Impact:
Enabling BitLocker on a device with third party encryption may render the device unusable and will require reinstallation of Windows.