Protect Data Before Windows Starts: BitLocker Startup Authentication via Intune
Key Takeaways
Ensures consistent pre-boot security across all managed Windows devices
Significantly reduces the risk of data exposure on lost or stolen devices
Enforces secure BitLocker startup authentication methods after policy deployment
Addresses gaps where devices may lack strong startup protection by default
Why BitLocker Startup Authentication Matters
When it comes to endpoint security, protecting data after Windows loads is no longer enough. One of the most critical attack windows exists before the operating system even starts.
BitLocker Startup Authentication plays a key role in closing that gap.
This policy controls how BitLocker authenticates a device during startup, determining whether the system relies on:
TPM only
TPM with PIN
Startup key
Or a combination of these methods
By configuring this policy through Microsoft Intune, administrators can ensure that all managed devices follow the same security rules at boot time, long before Windows and user credentials are loaded.
Protecting Data When Devices Are Lost or Stolen
Lost or stolen devices remain one of the most common causes of data breaches. Without proper startup authentication, an attacker could attempt to:
Boot the device using external media
Remove the hard drive and connect it to another system
Bypass weak or inconsistent pre-boot protections
BitLocker Startup Authentication prevents these scenarios.
By enforcing strong authentication before Windows starts, the encrypted drive remains inaccessible to anyone who is not authorized even if the hardware is physically compromised.
An Additional Layer of Security Before Windows Loads
Enabling startup authentication adds a critical security layer at the earliest possible stage of the device lifecycle.
Even in advanced attack scenarios where the hard drive is removed or the device is tampered with, the data remains encrypted and unusable. This dramatically reduces the risk of:
Data leakage
Unauthorized access
Offline attacks against encrypted volumes
In short, data stays protected regardless of physical access.
Operational Benefits for IT and Security Teams
From an organizational perspective, this policy delivers more than just security it provides control and consistency at scale.
By managing BitLocker startup authentication centrally through Intune, IT teams can:
Enforce standardized security requirements across all devices
Eliminate manual or inconsistent BitLocker configurations
Align devices with internal security baselines and compliance frameworks
Reduce operational overhead while improving overall security posture
Advantages of Enabling BitLocker Startup Authentication via Intune
Enforcing this policy through Intune delivers clear, measurable benefits:
Protects data before Windows loads
Prevents unauthorized access to encrypted drives
Standardizes BitLocker behavior across all managed devices
Reduces impact in lost or stolen device scenarios
Simplifies security management through centralized policy enforcement
Final Thoughts
BitLocker Startup Authentication ensures that devices are secured from power-on to shutdown.
It protects sensitive data, supports compliance requirements, and gives administrators confidence that endpoints remain secure even in the face of physical theft or tampering.
In modern environments, pre-boot protection is no longer optional. With Intune, enforcing it becomes consistent, scalable, and reliable.
How to Configure BitLocker Startup Authentication Using Intune (Settings Catalog)
You can enforce BitLocker startup authentication centrally using the Intune Settings Catalog, ensuring consistent protection across all managed Windows devices.
To begin, sign in to the Microsoft Intune admin center and follow the steps below, as illustrated in the screenshot.
Create the Configuration Profile
In the Microsoft Intune admin center, navigate to Devices
Select Windows
Click Configuration
Select + Create policy
In the Create a profile pane:
Platform: Windows 10 and later
Profile type: Settings catalog
Click Create to continue.

At this point, you’ve created the foundation of a Settings Catalog policy. In the next steps, you will locate and configure the BitLocker settings that define startup authentication behavior, such as TPM, TPM with PIN, or startup key, ensuring data is protected before Windows even starts and consistently enforced across all managed devices.
Define Basic Profile Details
After clicking Create, the next step is to define the basic details of the configuration profile. This stage is essential for long-term management, clarity, and governance within Microsoft Intune, especially in environments with multiple security baselines and device configuration policies.
Providing a clear Name and a concise but meaningful Description ensures that the purpose of the policy is immediately understood by administrators and security teams, both now and in the future.
As shown in the screenshot, configure the fields as follows:
Suggested Name and Description
Name: Enforce BitLocker Startup Authentication
Description: This policy enforces BitLocker startup authentication on Windows devices to protect data before the operating system loads. It ensures consistent pre-boot security by requiring trusted authentication methods such as TPM, TPM with PIN, or startup key, reducing the risk of data exposure if a device is lost or stolen.
The Platform field is automatically set to Windows, so no changes are required.
Once the name and description are defined, click Next to proceed to the configuration settings.

Configure BitLocker Startup Authentication Using the Settings Picker
With the profile basics defined, the next step is to configure BitLocker startup authentication using the Settings Catalog, where you explicitly define how BitLocker protects the device before Windows starts.
This configuration ensures that pre-boot authentication is enforced consistently across all managed Windows devices, significantly reducing the risk of offline attacks and data exposure.
Add and Locate the Required Setting
Click Add settings to open the Settings picker panel.
In the search field at the top of the Settings picker, type: Require additional authentication at startup
Click Search to filter the available settings.
From the results, navigate to the category: Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives
Select the setting: Require additional authentication at startup
Once selected, the setting is added to the configuration profile.
Enable and Configure Startup Authentication
Important: By default, this policy is not configured, which effectively means it behaves as Disabled. In this state, BitLocker does not enforce additional startup authentication requirements.
To properly secure devices, you must explicitly enable this setting.
6️. Set Require additional authentication at startup to Enabled.
Once enabled, the additional BitLocker startup options become available for configuration.
As shown in the screenshot, you can now define how BitLocker behaves during the boot process, including:
7️. Allow BitLocker without a compatible TPM Enable this option only if you need to support devices without TPM hardware (for example, using a startup key on a USB drive).
8️. Configure the allowed authentication methods, such as:
TPM only
TPM + PIN
TPM + startup key
Startup key only (for non-TPM scenarios)
These options allow organizations to balance security requirements, hardware capabilities, and user experience, while still enforcing strong pre-boot protection.
Why This Configuration Matters
Enabling Require additional authentication at startup ensures that BitLocker protects the device before the operating system loads, not just after a user signs in.
This means:
Stolen or lost devices remain protected even if the hard drive is removed
Offline attacks against encrypted disks are effectively blocked
Startup security behavior is standardized across all managed endpoints
Security controls are enforced silently, without user disruption
This approach aligns perfectly with Zero Trust and defense-in-depth strategies, ensuring that access to data is never assumed even at boot time.
After configuring the required options, click Next to continue with scope tags, assignments, and final deployment validation.

Configure Scope Tags (Optional)
Scope tags are used to control who can view and manage this policy within the Microsoft Intune admin center. They are particularly useful in environments with delegated administration, multiple IT teams, or regional management models.
As shown in the screenshot, the Default scope tag is selected. This is the standard and recommended configuration for most environments, as it ensures the policy is visible to all administrators who have access to Intune.
Optionally, custom scope tags can be assigned if you need to:
Restrict policy visibility to specific IT roles or teams
Enforce administrative separation of duties
Support delegated or region-based Intune management
If no additional scope tags are required, keep the Default selection and click Next to continue.

Assignments – BitLocker Startup Authentication Policy
After configuring the BitLocker startup authentication settings, the next step is to assign the policy to the appropriate target group. Assignments determine which devices will receive and enforce the pre-boot protection, ensuring the configuration is applied in a controlled and intentional manner.
In the Assignments tab, click Add groups under Included groups and search for the target group. This approach allows you to deploy the policy in phases, starting with test devices before expanding to production.
As shown in the screenshot, the policy is assigned to the following group:
GRP – MS365Education – Test Computers
Once the group is selected, verify the following:
The group appears under Included groups
The group status is Active
No assignment filters are applied (unless explicitly required)
At this stage, no Excluded groups are configured, which is appropriate for controlled testing of BitLocker startup authentication behavior.
After confirming the assignment, click Next to proceed to the Review + Create step.

Review + Create – Final Validation
The Review + Create step is the final checkpoint before deploying the BitLocker Startup Authentication policy. This is where you validate that all configurations are correct and aligned with your pre-boot security objectives.
Carefully review the following items:
Policy name and description Confirm the policy clearly reflects its purpose: enforcing BitLocker startup authentication to protect data before the operating system loads.
Configuration settings Verify that Require additional authentication at startup is set to Enabled, and that the selected startup authentication options (TPM, TPM with PIN, or startup key) match your organization’s security requirements.
Scope tags Ensure the correct scope tag is assigned. In this example, the Default scope tag is used, which is appropriate for most environments.
Assignments Confirm the policy is assigned to the intended group: GRP – MS365Education – Test Computers, and that no unintended exclusions are configured.
This final validation step helps prevent misconfigurations, unexpected startup behavior, or deployment issues especially when managing multiple BitLocker and security baseline policies.
Once everything has been reviewed and confirmed, click Create to finalize and deploy the policy to the assigned devices.

Monitor Policy Deployment Status
After creating and assigning the Enforce BitLocker Startup Authentication configuration profile, the next critical step is to monitor its deployment status. This verification ensures that the policy has been successfully applied and that pre-boot authentication is actively enforced on targeted devices.
Although Microsoft Intune may take up to 8 hours to deliver configuration profiles automatically, deployment often completes much faster. If needed, you can accelerate the process by:
Manually triggering a device sync from the Company Portal
Forcing a sync directly from the Microsoft Intune admin center
How to Verify Policy Deployment Status
To review deployment results:
In the Microsoft Intune admin center, navigate to: Devices ➝ Configuration profiles
Use the search bar to locate the profile: Enforce BitLocker Startup Authentication
Select the policy to open the Overview page.
Review Deployment Metrics
As shown in the screenshot, Intune provides clear deployment indicators:
Succeeded – Devices successfully applied the BitLocker startup authentication policy
In progress – Devices are still processing or have not checked in yet
Error – The policy failed to apply and requires investigation
Not applicable – The device does not support this BitLocker configuration
In this example, all targeted devices report Succeeded, confirming that BitLocker startup authentication is now fully enforced and protecting data before the operating system loads.

Client-Side Verification via Event Viewer
After the device has synced with Intune and applied the BitLocker Startup Authentication policy, you can perform a client-side verification to confirm that the configuration was successfully enforced. This validation is especially useful for troubleshooting and for ensuring that pre-boot authentication is active at the operating system level.
Windows records Intune policy processing events locally, allowing administrators to verify enforcement without relying solely on the Intune admin center.
How to Verify
Open Event Viewer on the target device
Navigate to: Applications and Services Logs ➝ Microsoft ➝ Windows ➝ DeviceManagement-Enterprise-Diagnostics-Provider ➝ Admin
Select Filter Current Log…
Look for Event ID 813 or Event ID 814, which indicate successful processing of Intune configuration policies
Open the event details and confirm that the BitLocker-related setting “Require additional authentication at startup” was applied successfully
Pro Tip: Match the event timestamp with the device’s most recent Intune sync. Event IDs 813 and 814 are the most reliable indicators that the BitLocker startup authentication policy was evaluated and enforced by the MDM engine.
Why This Validation Matters
BitLocker Startup Authentication is a critical pre-boot security control. Without proper enforcement, attackers with physical access can attempt offline attacks by removing the hard drive or booting from external media.
By enforcing this policy through Intune and validating it locally, organizations ensure that:
Pre-boot authentication is enforced before Windows loads
Unauthorized access to encrypted drives is prevented
Data remains protected even if the device is lost or stolen
BitLocker operates according to defined security standards
Endpoint protection starts at power-on, not at user sign-in
Key Takeaway
Strong endpoint security starts before the operating system loads.
By enforcing BitLocker Startup Authentication via Intune and validating it at the client level, organizations significantly reduce the risk of offline data access and device-based attacks. This policy delivers powerful protection with minimal operational overhead, ensuring data remains secure from startup to shutdown.
More Information
For additional technical details, official documentation, and deeper insights into BitLocker startup authentication and Microsoft Intune configuration, refer to the Microsoft Learn resources below:
Policy CSP – BitLocker Official reference for BitLocker policies exposed through MDM, including startup authentication, TPM, PIN, and startup key configurations. https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-bitlocker
Require Additional Authentication at Startup (BitLocker) Detailed explanation of how BitLocker startup authentication works, including TPM-only, TPM + PIN, and startup key scenarios. https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#require-additional-authentication-at-startup
Create a Settings Catalog Policy in Microsoft Intune Step-by-step guidance on creating and managing Settings Catalog policies for Windows devices using Intune. https://learn.microsoft.com/en-us/mem/intune/configuration/settings-catalog
BitLocker Deployment and Management with Intune Overview of how BitLocker encryption and key management are handled in Intune-managed environments. https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices
Monitor Intune Policy Deployment and Troubleshoot Profiles Learn how to monitor deployment status, interpret errors, and troubleshoot BitLocker and configuration profile issues. https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot
Event Viewer Logs for MDM and Intune Diagnostics Detailed explanation of client-side Event Viewer logs used to validate Intune policy processing and enforcement. https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot#event-viewer-logs
Thank you!
🖥️ Ricardo Barbosa
🎖️ Microsoft MVP | 📘 Microsoft Certified Trainer (MCT)
☁️ Intune & Cloud Architect |💼 Technology Director at Altelix.com
