Skip to main content
Cybersecurity

BitLocker Encryption for Small Business

BitLocker Encryption for Small Business

Here’s the short version: BitLocker encryption for small business means a stolen Windows laptop is a hardware problem, not a client-file problem. Escrow the recovery keys. Use Pro, not Home. Intune can enforce it. BitLocker does not encrypt Microsoft 365.

A laptop in an Uber is a cliche because it keeps happening. Without encryption, whoever has the disk has the Outlook cache, the downloads folder, and whatever someone saved “just this once.” With BitLocker and a key you control, they have a paperweight.

Microsoft documents BitLocker and Intune disk encryption. Use those as the how. This page is the why and the order for a 10 to 80 person firm.

If devices are not in Intune yet, that is the first project. Encryption policy on unmanaged Home PCs is a wish.

What BitLocker encryption does and does not

It encrypts the OS volume (and other volumes you specify) so data at rest is not readable without the key. TPM plus a PIN is stronger than TPM-only. TPM-only is still far better than off. Microsoft’s BitLocker countermeasures page is the threat model: stolen disk, evil maid, offline attack. It is not “the thief who is already signed in.”

It does not:

  • Stop a signed-in thief who has the password and an unlocked session
  • Encrypt SharePoint
  • Replace MFA
  • Replace backup
  • Work the way you want on Windows Home

HIPAA language about encryption at rest is a technical safeguard. The rule is in 45 CFR 164.312. Encryption is addressable, not a sticker. BitLocker on laptops that leave the clinic is how many firms implement the endpoint part. It is not a HIPAA certification. See the HIPAA checklist for the rest of that story.

Recovery keys are the actual project

Encryption without recovery is how you lose a laptop twice: once to theft, once to a failed TPM after a firmware update.

Microsoft’s BitLocker recovery overview is the product doc. For Entra-joined devices, store the recovery key in Microsoft Entra ID. That is the copy help desk can pull. A USB in a drawer, a screenshot in camera roll, and “the user printed it” are not a program.

Confirm you can see a key for a test device in Intune or Entra. Do a recovery on a spare. Write the steps next to help desk. Users should not be the only copy of the key.

If a user “lost” the key and you cannot recover, the disk is gone. That is the design. Plan for it.

Set Intune so recovery information is stored in Entra before encryption starts. If the disk encrypts and escrow fails, you have a locked brick with no key in the portal. Silent encryption that requires escrow first is the grown-up setting.

After someone uses a recovery key on a support call, rotate it. The old 48-digit string was read out loud. Treat it as exposed.

If a device is already encrypted and the portal says no key, do not decrypt to “start over.” Check that the PC is Entra joined. Then escrow the existing protector. Decrypting a working disk to chase a portal blank is how you spend a day copying a user’s desktop. Missing key is an escrow problem until you prove otherwise.

Closed laptop on an office desk
A stolen unencrypted laptop is a data incident, not just a hardware ticket

Intune is how you make it real

A GPO in an office nobody uses is not a fleet. Intune encryption policy on enrolled Pro devices can enable BitLocker silently, require TPM, and escrow keys. Pilot ten devices. Then everyone.

Autopilot plus encryption on first sign-in is the clean version. See the Intune without recalling every laptop study for enrollment. Encryption is the follow-on policy, not a separate religion.

The device must be Entra joined or hybrid joined for key escrow to Entra. “Entra registered” consumer-style join is not the same. If keys are missing in the portal, check join state before you decrypt anything.

TPM-only vs TPM plus PIN

TPM-only is quieter. TPM plus PIN is stronger against some offline and pre-boot attacks. Most small offices start TPM-only so people do not forget a PIN and call daily. Add PIN for executives and finance laptops if the extra prompt is acceptable. Do not mix randomly. Help desk needs one story.

Firmware updates are the classic surprise. TPM handoff after a BIOS change puts Windows on the recovery screen. The disk is still encrypted. If the key is in Entra, help desk pulls it and the user is in. If the key is in a screenshot on the encrypted disk, you are in a loop. Tell people: if you see a BitLocker recovery screen, call us, do not guess.

For a planned BIOS update, IT can suspend BitLocker for one reboot, patch, then resume. Users should not be the ones suspending protection. A fleet that lives with BitLocker suspended is a fleet that is not encrypted.

Home vs Pro is the delay

Device encryption on some Home SKUs is a related feature with less control. BitLocker on Pro or Enterprise is what you manage with Intune, recovery keys in Entra, and a real policy. Do not buy Home PCs on a sale and hope.

Inventory first: OS edition, TPM present, Intune enrolled, already encrypted or not. Upgrade Home to Pro where needed. That upgrade is the delay. Budget it before the sale laptop.

Consumer PCs also skip Autopilot more often. You will enroll them later, by hand, which is how encryption policy never quite covers the fleet.

Used-space-only encryption finishes faster and looks done. Full encryption takes longer and is the one you want on a laptop that already had files on it. New Autopilot devices can encrypt early. A three-year-old sales laptop should not get the shortcut. Intune compliance should show encrypted, key escrowed, not “encryption in progress” forever.

Macs are FileVault, not BitLocker

If you have both, say both. Do not tell an insurer you “do BitLocker” when half the firm is on Macs with FileVault off. Apple documents FileVault. Intune can encrypt macOS with FileVault and escrow those keys too, on enrolled Macs.

Personal Macs with no MDM are a different conversation. Company Macs should be enrolled and FileVaulted. “We BitLocker Windows” is not an answer for the Mac that holds the same mailbox.

Laptop bag in an office
Escrow BitLocker keys in Entra and test recovery on a spare device

A two-week enable

Week 1: inventory

OS edition, TPM present, Intune enrolled, any already encrypted. Upgrade Home to Pro where needed.

Week 2: policy and a spare

Intune encryption policy with escrow required first. Recover a spare. Then target a pilot group. Then all enrolled Windows devices. Tell people they might see a one-time blip. They should not see a daily PIN unless you chose that.

A 12-laptop firm we worked with bought consumer PCs on a sale. They were Windows Home. Intune encryption policy would not do what we needed. We upgraded to Pro, enrolled, escrowed keys, recovered a spare after a BIOS change in the office. Two weeks later a laptop was stolen from a car. Intune wipe, password reset, sessions revoked, BitLocker on. The police report was a hardware loss. It was not a client-notification event. That difference is the whole product.

What a lost laptop ticket should include

Serial, user, last Intune check-in, whether BitLocker was on, whether you wiped via Intune, whether you rotated the user’s password and sessions. Encryption is one line in that ticket, not the whole ticket. Offboarding still applies if the device will not come back.

“Windows laptops that leave the office are BitLocker encrypted, keys escrowed in Entra, recovery tested [date]” is a sentence. “We think Windows encrypts by default” is not. Measure, then write.

Cybersecurity for endpoints is EDR plus encryption plus enrollment. Encryption alone is not EDR. EDR alone is not encryption. Cyber insurance questionnaires ask whether portable devices are encrypted. Answer from Intune compliance, not from a feeling. A device that is “probably encrypted because Windows asked once” is not a yes.

Printable BitLocker checklist

  1. Count devices by OS edition. Upgrade Home to Pro.
  2. Confirm TPM. Confirm Intune enrollment. Entra joined, not only registered.
  3. Escrow policy to Entra before encryption starts. No user-only keys.
  4. Recover a spare. Document the clicks for help desk.
  5. Pilot ten. Then the fleet.
  6. Macs: FileVault, separately, honestly, keys escrowed.
  7. Lost-laptop ticket includes wipe, password, sessions, encryption state.
  8. After BIOS updates, expect a recovery-key ticket. That is normal.
  9. After a recovery, rotate the key.
  10. Insurance sentence: encrypted, keys escrowed, recovery tested on [date]. Re-check escrow coverage quarterly. New PCs drift.

If step 4 has never happened, you do not have encryption you can operate. You have a setting.

If you want BitLocker on the fleet with keys you can actually find, contact Secure Techies. We work from Canoga Park. We will check editions, escrow, and a spare recovery before we call it done. Bring a device count by Windows edition. Home SKUs are the delay.

Frequently Asked Questions

If you have Windows laptops that leave the office, yes. An unencrypted stolen laptop is a data incident. BitLocker encrypts the drive so the thief has a brick unless they have the key. Insurance and client questionnaires ask this for a reason.
Device encryption on some Home SKUs is a related feature with less control. BitLocker on Pro or Enterprise is what you manage with Intune, recovery keys in Entra, and a real policy. Do not buy Home PCs and hope.
In Entra ID (or Active Directory) so IT can recover a machine, and not only on a USB in a drawer nobody can find. Users should not be the only people who can unlock a company laptop. Test a recovery before you need one.
No. BitLocker protects the local disk. SharePoint, Exchange, and OneDrive have their own controls. Encrypting a laptop does not encrypt the tenant. You still need MFA, sharing defaults, and backup.
Yes, on supported Windows editions with the right enrollment. Microsoft documents device encryption policies in Intune. Silent enable is the goal so users do not get a puzzle on Monday morning. Pilot first.
Share

Talk to a real IT expert — free

No sales pressure, no jargon. Just a straight assessment of where your IT and security stand, and what to do next.