Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Windows » Why is BitLocker unable to encrypt Removable Drives via MBAM?
  • Install ROOT CA Enterprise
    How to Install ROOT CA Enterprise and NPS Wifi Certificate Windows
  • xvy
    Fix Error 0xc1420127: The specified image in the specified wim is already mounted for read and write access Windows Server
  • Windows 11 New Security Features
    Smart App Control: Enabling Phishing Protection in Windows 11 Windows
  • images 1
    WARNING: The provided hosts list is empty only the localhost is available and note that the implicit localhost does not match all Configuration Management Tool
  • aptira ansible 1
    The module ping was not found in configured module paths, core modules are missing Configuration Management Tool
  • Prevent Windows from Saving RDP Connection
    Prevent Windows from Saving RDP Connection History Windows
  • the remote procedure call failed
    Error 0xc1420117: The directory could not be completely unmounted Windows Server
  • image 63
    What to do when your Remote Desktop Licensing Manager Server Crashes Windows

Why is BitLocker unable to encrypt Removable Drives via MBAM?

Posted on 05/11/202405/11/2024 Christian By Christian No Comments on Why is BitLocker unable to encrypt Removable Drives via MBAM?
Fixed drives not encrypted by BitLocker via MBAM

Fixed Data Drives refer to non-removable storage drives installed in a PC such as internal hard drives (HDDs) or solid-state drives (SSDs). Unlike removable drives (like USB flash drives). Fixed drives are used to store data, applications, and the operating system. In this article, we shall discuss how to resolve ‘Why is BitLocker unable to encrypt Removable Drives via MBAM?”. Please see Why does MBAM not automatically re-encrypt MBAM or Bitlocker-protected devices and how does Key Rotation work in MBAM?

It makes sense to differentiate between the Operating System Drive and Data drive. The operating System Drive is a volume where the operating system (OS) is installed. This drive contains all the necessary files for the OS to function, including system files, drivers, and core applications.

While the Data Drive is a separate storage volume used primarily for storing user data. This includes applications, and files that do not directly affect the operating system’s functionalities.

Scenario 1: OS Volume Encrypted

As you can see from the image below, the OS volume is encrypted correctly but the Removable Drive (volume E and D) are not. This is NOT an issue and does not need to be fixed as we only have policies configured for the OS drives and Data drives.

This is because, we have not configured MBAM/BitLocker polices to have removable drives encrypted.

BitLocker-status

As you can see from the Enterprise Compliance Report, there are no errors. Only the OS drive is available and encrypted.

MBAM Computer Compliance reports

Note: If the OS drives were encrypted and then the data drives aren’t. Then this would have been an issues and this could be as a result of the device not in contact with the domain. Re-apply GPO to fix this issue.

Please see How to prevent installation of removable devices, How to restrict access to removable Storage Drives, and how to Disable and Enable USB Usage for Certain Users in Windows.

OS Drive, Data Drive Encrypted: But not Removable Drives

Note: in the world of MBAM, the OS drives and fixed drives will be encrypted when the agent is installed. But will never encrypt external drives such as USB or hard disk etc.

The Volume E is a USB drive and as mentioned above. I have not configured Group Polices to target these external drives and have them encrypted.

Also did not encrzpt the external drive
I do not have a group policy configured to have removable drives such as USB encrypted.

Please see how to Deny execute access: Restrict Access to USB Drives on Windows, and how to link a removable media to a Deployment Share: Replicate Deployment share to a removable device.

FAQs

Does BitLocker Drive Encryption require initial encryption?

BitLocker Drive Encryption does not require a pre-installation of BitLocker on your end device. Else, the Trellix Drive Encryption will not start due to incompatibility.

What features does the Trellix Native Encryption provide?

The solution identifies unprotected Windows or Mac devices, deploys agents based on configured policies, stores audit and logging information within the MVISION ePO or McAfee ePO console, and allows you to specify new encryption policies at any organizational level to address specific use cases.

I hope you found this article very useful on “Why is BitLocker unable to encrypt Removable Drives via MBAM?”. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:Windows 10, Windows 11

Post navigation

Previous Post: BitLocker Protection off: Update UEFI/BIOS to fix issues
Next Post: Apache errors associated with WAMP installation for TeamPass

Related Posts

  • maxresdefault
    How to stop Microsoft Edge from remembering your email ID Windows
  • screenshot 2020 02 07 at 21.59.33
    Prerequisites for setting up a Single and Multi App Kiosk Windows
  • How to install and configure a Standalone DNS Server
    How to Install and Configure a Standalone DNS Server Windows Server
  • windows hello la gi
    All you need to know before deploying Windows Hello for Business Key and Certificate Trust Windows
  • How to Find Out Which Users Are Logged on Windows Server
    How to Find Out Which Users Are Logged on Windows Server Windows
  • Enable only Windows Admin to shutdown PC
    Allow only Administrators to shut down and reboot Server Windows

More Related Articles

maxresdefault How to stop Microsoft Edge from remembering your email ID Windows
screenshot 2020 02 07 at 21.59.33 Prerequisites for setting up a Single and Multi App Kiosk Windows
How to install and configure a Standalone DNS Server How to Install and Configure a Standalone DNS Server Windows Server
windows hello la gi All you need to know before deploying Windows Hello for Business Key and Certificate Trust Windows
How to Find Out Which Users Are Logged on Windows Server How to Find Out Which Users Are Logged on Windows Server Windows
Enable only Windows Admin to shutdown PC Allow only Administrators to shut down and reboot Server Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Install ROOT CA Enterprise
    How to Install ROOT CA Enterprise and NPS Wifi Certificate Windows
  • xvy
    Fix Error 0xc1420127: The specified image in the specified wim is already mounted for read and write access Windows Server
  • Windows 11 New Security Features
    Smart App Control: Enabling Phishing Protection in Windows 11 Windows
  • images 1
    WARNING: The provided hosts list is empty only the localhost is available and note that the implicit localhost does not match all Configuration Management Tool
  • aptira ansible 1
    The module ping was not found in configured module paths, core modules are missing Configuration Management Tool
  • Prevent Windows from Saving RDP Connection
    Prevent Windows from Saving RDP Connection History Windows
  • the remote procedure call failed
    Error 0xc1420117: The directory could not be completely unmounted Windows Server
  • image 63
    What to do when your Remote Desktop Licensing Manager Server Crashes Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,825 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.