Skip to main content

Disk Encryption- Status

Disk Encryption manages BitLocker on your Windows endpoints. The Status tab is where you land: a live picture of which drives are encrypted, how far along they are, and whether the TPM (the security chip BitLocker relies on) is available.

Edition & permission

Device Control is EndpointOps edition. You need View BitLocker permission.

How to get here

  1. In the left sidebar, click Device Control.
  2. Click the Disk Encryption card.

Navigate to: Device Control → Disk Encryption → Status

URL path: /device-control/bitlocker-settings/status

The Status screen

The Disk Encryption status screen with per-drive encryption stateThe Disk Encryption status screen with per-drive encryption state

Across the whole fleet, two charts summarise Encryption Status and TPM Availability. The table lists each drive:

ColumnWhat it shows
EndpointThe machine (fleet-wide view only).
Applied PolicyThe BitLocker policy in effect.
DriveDrive letter with a protection-status lock.
Encryption StatusFully Encrypted, Encryption in Progress, Decryption in Progress, Fully Decrypted.
Protection StatusProtected / Unprotected / Partially Protected.
Lock StatusLocked / Unlocked.
Encryption (%)How far encryption has progressed.
Volume SizeDrive size.
Last Updated AtWhen the status last refreshed.

The column picker adds volume and TPM detail- Volume Name / ID, Encryption Method, Volume Type, and the TPM fields (Available, Enabled, Activated, Owned, Manufacturer, Version).

On a single endpoint's view you also get Scan Drive Status (trigger a live scan) and Drive Scan History (a drawer of past scans).

Tips & troubleshooting

  • A drive shows Unprotected at 100%. Encryption can be complete while protection is suspended- check the Protection Status and the applied policy.
  • No TPM. Some policies allow encryption without a TPM; see the policy options.