# Possible Causes of BitLocker Encryption Failure This page explains the possible causes of BitLocker encryption failure in Endpoint Central and provides resolution steps for each scenario. If your machine is not getting encrypted, work through the checks below in order. ## License Validation If a limited license for BitLocker has been purchased, ensure the system is added to Endpoint Security before expecting encryption to proceed. 1. Open the Endpoint Central console and navigate to **Admin → Global Settings → Endpoint Security**. 2. Add the system to Endpoint Security. Once added, the BitLocker component will be enabled during the next agent refresh, and the Drive Encryption Policy will be applied. For recovery key retrieval issues related to missing keys or WMI collection failures, see [Recovery Key Troubleshooting > Recovery Key Not Found](https://www.manageengine.com/products/desktop-central/help/bitlocker-management/kb/bitlocker-recovery-key-troubleshooting.html#recovery-key-not-found). ## Agent-Server / Distribution Server Connectivity Verify that the agent can communicate with the server or Distribution Server without issues. **Note:** If the machine is managed under a Distribution Server, the deployed policy will be applied only after the Distribution Server completes its replication cycle, followed by the agent's next refresh cycle. ## Policy Deployment Conflicts Check whether the machine is part of multiple custom groups. When a machine belongs to more than one custom group, only the last deployed policy is applied — all other policies remain in a **Yet to apply** state. To resolve this, ensure the machine belongs to only one custom group, or review the group targeting of your BitLocker policies to avoid overlap. ## Encryption Prerequisites Confirm whether all encryption prerequisites are satisfied. Prerequisite failures can be viewed in either of the following ways: 1. Navigate to **BitLocker Management → Managed Computers** and view the status of the specific computer. 2. Navigate to **BitLocker Management → Encryption Prerequisites** — all prerequisite failures are listed here. ## Server OS Consideration If the device runs a server operating system, confirm that BitLocker is supported and enabled on that OS edition. Refer to the [BitLocker availability reference](https://www.manageengine.com/products/desktop-central/help/bitlocker-management/bitlocker-pre-requisites.html#avail) for the list of supported server OS editions. ## Non-TPM Devices For machines without a TPM chip, ensure the associated BitLocker policy is configured to use **Passphrase** as the key protector. Policies that require TPM will fail silently on non-TPM hardware. To check TPM availability, navigate to **BitLocker Management → Managed Computers** and review the **TPM Status** column for the specific machine. ![BitLocker Managed Computers view showing the TPM Status column for each managed device](https://www.manageengine.com/products/desktop-central/help/images/tpm-status.png) BitLocker Managed Computers view — the TPM Status column indicates whether a TPM chip is present on each device. ## Portable Drives (Unsupported) BitLocker Management does not support encryption of portable or removable drives. To confirm whether a drive is classified as removable, open **Control Panel → System and Security → BitLocker Drive Encryption** and check whether the drive appears under **Removable data drives**. ![Windows Control Panel BitLocker Drive Encryption screen showing a drive listed under Removable data drives](https://www.manageengine.com/products/desktop-central/help/images/ctrl-panel-bitlocker.png) Control Panel → BitLocker Drive Encryption — drives listed under Removable data drives are not supported by BitLocker Management. **Note:** BitLocker Management does not support encryption of portable drives. To encrypt removable drives, use the [USB encryption feature in the Device Control module](https://www.manageengine.com/products/desktop-central/help/device-control/create-dc-policy.html#windows-removable-storage-device). ## Locked Data Drive Verify whether the data drive (for example, D:) is unlocked. Navigate to **BitLocker Management → Managed Computers** and review the **Lock Status** column for the specific machine. If the drive is locked, it must be unlocked before BitLocker operations can proceed. Retrieve the recovery key using your tool or the medium through which it was originally encrypted, then unlock the drive before retrying. ## Still Having Issues? If the encryption failure persists after working through all the checks above, [upload the log file](https://www.manageengine.com/products/desktop-central/logs-how-to.html) and contact [endpointcentral-support@manageengine.com](mailto:endpointcentral-support@manageengine.com) with the logs attached. ## Related - [BitLocker Management Prerequisites](https://www.manageengine.com/products/desktop-central/help/bitlocker-management/bitlocker-pre-requisites.html) - [USB Encryption via Device Control](https://www.manageengine.com/products/desktop-central/help/device-control/create-dc-policy.html#windows-removable-storage-device) - [BitLocker Management Overview](https://www.manageengine.com/products/desktop-central/help/bitlocker-management/bitlocker-overview.html)