BitLocker Policy Association & Deployment
Associate a BitLocker policy with a target group, deploy it, and confirm devices actually encrypt.
Overview
Associating a policy with targets
A policy has to be linked to a target group before it can deploy.
How association works
A policy created in the BitLocker module (see policy creation) has to be associated with a target before it deploys anywhere.
Supported target types are static computer groups, static unique computer groups, and dynamic computer groups. Any new system that joins a dynamic group and matches its criteria gets encrypted automatically under the deployed policy, with no manual step required. More on configuring custom groups.
Deployment
Deploying the policy
Pick a target group, attach one policy to it, and deploy.
Associate and deploy a policy
- Go to Policy Deployment under the BitLocker Management module in the Endpoint Central web console.
- Click Associate Policy.

Starting policy association. - Select the custom group to deploy the policy to. To automate deployment for every new device, select All Computers Group — new computers join this group automatically, so they're encrypted automatically too.

Selecting a target group for automatic deployment. - Choose the BitLocker policy to associate with the group (only one policy per group is allowed).

Selecting the policy to associate. - Click Deploy.
Monitoring
Confirming devices actually encrypted
Deployment status and encryption status are two different things to check.
Checking deployment and encryption status
After deployment, the associated-computers list under Managed Computers shows each device's policy deployment status, along with remarks or reasons for any failures. Confirm encryption is either in progress or complete — a successful deployment doesn't by itself guarantee a device is encrypted.

A machine can stay fully decrypted even after a successful deployment for two common reasons: the policy needs a user-entered PIN or passphrase, or it's a non-TPM machine where a passphrase is mandatory. Environmental issues can also cause failures — check encryption prerequisites for machines blocked by BIOS mode incompatibility, WMI failures, or TPM ownership issues, each documented with remediation steps.
Passwords
Password requirements before encryption starts
Encryption only begins once a compliant password has been set — the rules differ by authentication type.
Password criteria by authentication type


