BitLocker Audit & Reports
Where to check per-device encryption status, and what the BitLocker and TPM reports actually show.
Overview
Managed Computers
One view summarizes every device's encryption state, policy, and prerequisite status.
What the Managed Computers view shows
The Managed Computers section under Insights lists, for each device: its name, domain, operating system, storage capacity, encryption status, applied policy, BitLocker and TPM availability, and BitLocker component and prerequisite statuses.

Reading the Encryption Status icon
Encryption Status is a machine-level summary across all of a computer's drives. The color of the icon next to the status matters as much as the status text itself:

Reports
BitLocker Reports
Every computer is scanned for its BitLocker and drive details, starting right after agent installation.

What's in the status report
All computers are scanned to assess their BitLocker encryption status and drive details. The initial scan runs right after agent installation, and later scans detect new computers and track changes in drive status and encryption progress.
Reports
TPM Reports
TPM handles the hardware side of encryption, and its own report tracks whether it's available, enabled, and owned.

How TPM protects the drive
The Trusted Platform Module (TPM) is a hardware security chip on the motherboard that provides hardware-level drive encryption. It generates a set of cryptographic keys unique to the host system, storing part of the key in the TPM and the rest on the hard drive — the drive is only accessible when both halves match, so if the drive is moved to another computer, the data stays encrypted.