Possible Causes of BitLocker Encryption Failure
This page explains the possible causes of BitLocker encryption failure in Endpoint Central and provides resolution steps for each scenario. If your machine is not getting encrypted, work through the checks below in order.
License Validation
If a limited license for BitLocker has been purchased, ensure the system is added to Endpoint Security before expecting encryption to proceed.
- Open the Endpoint Central console and navigate to Admin → Global Settings → Endpoint Security.
- Add the system to Endpoint Security. Once added, the BitLocker component will be enabled during the next agent refresh, and the Drive Encryption Policy will be applied.
For recovery key retrieval issues related to missing keys or WMI collection failures, see Recovery Key Troubleshooting > Recovery Key Not Found.
Agent-Server / Distribution Server Connectivity
Verify that the agent can communicate with the server or Distribution Server without issues.
Policy Deployment Conflicts
Check whether the machine is part of multiple custom groups. When a machine belongs to more than one custom group, only the last deployed policy is applied — all other policies remain in a Yet to apply state.
To resolve this, ensure the machine belongs to only one custom group, or review the group targeting of your BitLocker policies to avoid overlap.
Encryption Prerequisites
Confirm whether all encryption prerequisites are satisfied. Prerequisite failures can be viewed in either of the following ways:
- Navigate to BitLocker Management → Managed Computers and view the status of the specific computer.
- Navigate to BitLocker Management → Encryption Prerequisites — all prerequisite failures are listed here.
Server OS Consideration
If the device runs a server operating system, confirm that BitLocker is supported and enabled on that OS edition. Refer to the BitLocker availability reference for the list of supported server OS editions.
Non-TPM Devices
For machines without a TPM chip, ensure the associated BitLocker policy is configured to use Passphrase as the key protector. Policies that require TPM will fail silently on non-TPM hardware.
To check TPM availability, navigate to BitLocker Management → Managed Computers and review the TPM Status column for the specific machine.

Portable Drives (Unsupported)
BitLocker Management does not support encryption of portable or removable drives. To confirm whether a drive is classified as removable, open Control Panel → System and Security → BitLocker Drive Encryption and check whether the drive appears under Removable data drives.

Locked Data Drive
Verify whether the data drive (for example, D:) is unlocked. Navigate to BitLocker Management → Managed Computers and review the Lock Status column for the specific machine.
If the drive is locked, it must be unlocked before BitLocker operations can proceed. Retrieve the recovery key using your tool or the medium through which it was originally encrypted, then unlock the drive before retrying.
Still Having Issues?
If the encryption failure persists after working through all the checks above, upload the log file and contact endpointcentral-support@manageengine.com with the logs attached.