Microsoft this week warned its customers about BitLocker encryption errors in some managed Windows.
See also: Iranian hackers encrypt Windows systems via BitLocker

According to the company, this known issue only affects client platforms , including Windows 11 21H2/22H2 , Windows 10 21H2/22H2 , and Windows 10 Enterprise LTSC 2019. The issue only affects environments where hard disk encryption is mandatory for the operating system and fixed disks.
Microsoft says Intune, cloud- , is one of the MDM platforms affected by the issue. However, it has not disclosed which other MDM applications are experiencing these BitLocker errors.
The company states in the Windows Health Dashboard that “using the FixedDrivesEncryptionType or SystemDrivesEncryptionType policy settings in the BitLocker Configuration Service Provider (CSP) in mobile device management (MDM) applications may incorrectly display a 65000 error in the “Device encryption required” setting for some devices in your environment.”
“The affected environments are those with the policies “Enforce drive encryption type on operating system drives” or “Enforce drive encryption on fixed drives” that are set to enabled and selecting either “full encryption” or “used space only”“.
See also: CHwapi: Windows BitLocker "hit" the Belgian hospital!

Microsoft also clarified that this error is caused by a reporting issue and does not affect disk encryption or reporting of other device issues, including other BitLocker issues on MDM-enrolled Windows devices
To address this, administrators can enable the “not configured” setting for “Enforce drive encryption type on operating system drives” or “Enforce drive encryption on fixed drives” in Microsoft Intune. The company said it is actively working to resolve the issue and will provide more details with an upcoming update.
Earlier this year, Microsoft addressed a known issue affecting WSUS (Windows Server Update Services) servers that were upgraded to Windows Server 2022, causing Windows 11 22H2 updates to stop being sent to enterprise endpoints. That same month, it fixed another bug that caused video recording and playback issues in applications that use the WVC1 codec on Windows 10 and Windows 11 systems
See also: How to set the minimum PIN length for BitLocker
BitLocker, an encryption technology offered by Microsoft, is designed to provide data protection in case of theft or lost devices. Possibly – and many are still comfortable with this assumption – what defines the quality of the security service is its ability to respond to interception environments and lost devices.
How does BitLocker technology work?
BitLocker is a full-disk encryptor that uses the cryptographic algorithm AES (Advanced Encryption Standard) with a 128- or 256-bit key to encrypt a computer's hard drive. Additionally, however, BitLocker provides a range of critical functions. It manages pre-boot unlock protection, platform integrity protection (TPM), and general interface protection.
Source: bleepingcomputer
