Skip to content

Commit a9682a1

Browse files
authored
Merge pull request #6684 from jasonsandys-microsoft/patch-6
Update bitlocker-management.md
2 parents 031c684 + c17e31f commit a9682a1

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

memdocs/configmgr/protect/plan-design/bitlocker-management.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Plan for BitLocker management
33
titleSuffix: Configuration Manager
44
description: Plan for managing BitLocker Drive Encryption with Configuration Manager.
5-
ms.date: 12/01/2021
5+
ms.date: 02/01/2022
66
ms.prod: configuration-manager
77
ms.technology: configmgr-protect
88
ms.topic: conceptual
@@ -135,7 +135,9 @@ BitLocker management doesn't support all client types that are generally support
135135

136136
- BitLocker management isn't supported on virtual machines (VMs) or on server editions. For example, BitLocker management won't start the encryption on fixed drives of virtual machines. Additionally fixed drives in virtual machines may show as compliant even though they aren't encrypted.
137137

138-
- Azure Active Directory (Azure AD)-joined, workgroup clients, or clients in untrusted domains aren't supported. BitLocker management in Configuration Manager only supports devices that are joined to on-premises Active Directory. Hybrid Azure AD-joined devices are also supported. This configuration is to authenticate with the recovery service to escrow keys.
138+
- In version 2010 and earlier, Azure Active Directory (Azure AD)-joined, workgroup clients, or clients in untrusted domains aren't supported. In these earlier versions of Configuration Manager, BitLocker management only supports devices that are joined to on-premises Active Directory including hybrid Azure AD-joined devices. This configuration is to authenticate with the recovery service to escrow keys.
139+
140+
Starting in version 2103, Configuration Manager supports all client join types for BitLocker management. However, the client-side BitLocker user interface component is still only supported on Active Directory-joined and hybrid Azure AD-joined devices.
139141

140142
- Starting in version 2010, you can now manage BitLocker policies and escrow recovery keys over a [cloud management gateway (CMG)](../../core/clients/manage/cmg/overview.md). This change also provides support for BitLocker management via internet-based client management (IBCM). There's no change to the setup process for BitLocker management. This improvement supports domain-joined and hybrid domain-joined devices.<!--6979223--> For more information, see [Deploy management agent: Recovery service](../deploy-use/bitlocker/recovery-service.md).
141143

0 commit comments

Comments
 (0)