Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel
  • sql
    How to alter a DATABASE compatibility level Oracle/MSSQL/MySQL
  • jhgfx
    How to make Cortana use your default web browser such as Google Chrome Windows
  • 1 8y62mmvjlr 5uovgoq6zmq
    How to download and install DriveLock on Windows Security | Vulnerability Scans and Assessment
  • Windows11
    How to change Regional Settings for all users on Windows 11 Windows
  • windows update 03
    Check if Windows Updates were installed via the Registry Editor Windows
  • Add or remove features   fix dotnet framework issues
    Fix the request to add or remove features on the specified server failed Windows
  • article 1280x720.13392821
    How to use command prompt to shutdown and restart your computer Windows
  • Prevent Local Administrators from turning off BitLocker 1
    Prevent Local Administrators from managing BitLocker with the manage-bde command Windows

BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel

Posted on 02/07/202507/09/2025 Christian By Christian No Comments on BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel
BitLocker beviour when MBAM Agent is removed - No uninstall options in control panel to remove app

MBAM (Microsoft BitLocker Administration and Monitoring) is a tool that enables you (organizations) to centrally manage and monitor BitLocker Drive Encryption across Windows devices. In this article, we shall discuss “BitLocker behavior when MBAM agent is removed: Remove MBAM Agent When Uninstall Option is missing”. Please, see Get a list of installed programs locally or remotely in Windows. Also, see how to get MBAM BitLocker Recovery Keys from Microsoft SQL Server.

Note: Admin rights are required when the app was installed system-wide. Please, see How to deploy MBAM for BitLocker Administration.

You may need to understand how BitLocker behaves if the MBAM agent is removed. Particularly if a suitable alternative product is not found before MBAM’s extended support ends in April 2026. Please, see MBAM extended support ends April 2026: Find alternative solution.

Here is how to Set Microsoft Defender AV to Passive mode on a Windows Server, and What you need to know about Microsoft Defender Antivirus. I would recommend reading how to Set Microsoft Defender Antivirus to Passive or Active Mode.

MBAM Agent Behavior on Uninstall

When you uninstall the MDOP MBAM Agent, the drive stays encrypted and BitLocker takes over management directly. Unlike devices still managed by MBAM, Group Policy hides the “Manage BitLocker” option, leaving only the “BitLocker Encryption Option” available for management.

As a result, you can no longer manage the device through the MBAM Helpdesk or Self-Service Portal. However, since the drive remains encrypted and the recovery key is escrowed to Active Directory (if configured via GPO), you must retrieve the key from AD going forward.

Please, see How to install Endpoint Configuration Manager on HyperV VM, and how to install Veeam Backup Console on a Jump Server. Also, see how to fix MSIEXEC returned 1602: Trellix Setup cannot use this account.

Remove MBAM Agent When Uninstall Option is missing

When there is no uninstall option in Control Panel for a program or app as shown below. It is often due to software management restrictions. Some of which are enforced by Microsoft Endpoint Configuration Manager (SCCM), Group Policy, or other enterprise deployment tools. such as Ivanti DSM. These tools can suppress the uninstall option to prevent end users from removing security-critical software.

Also, having the installer or deployment script might include parameters that disable user uninstallation (e.g., ARPNOREMOVE=1 in MSI-based installs). This prevents MBAM from appearing in “Add/Remove Programs” or disables the uninstall button.

No uninstall option

Therefore, when the “Uninstall and Change” options for an application are missing in Apps & Features on Windows are likely blocked by 3rd party management tool. You can try to uninstall the app via Command Prompt or PowerShell as discussed below

Please, see how to enable or disable a Remote WMI Connection in Windows. Also, see how to Enable and Disable WMI Traffic through Windows CMD, and Remote WMI Connection: How to enable or disable WMI Traffic Using Firewall UI.

Use wmic for installers (MSI)

You can use WMIC (Windows Management Instrumentation Command-line) to uninstall MSI-based applications by querying their product name or identifying number. This method is useful when the app doesn’t show up in Control Panel or the uninstall option is restricted.

To do this, replace the ‘AppName’ with the name of the application as shown in the image below.

wmic product where "name like 'AppName%%'" call uninstall
Uninstall MBAM
If the app is listed in wmic, this command will silently
uninstall it as shown
in this image

Please see Please see this detailed guide on Windows Management Instrumentation: WMI Commands, and how to uninstall installed Windows Update. Here is a guide on Fast Boot Options: Fix specific Drive issue with BitLocker [MBAM].

Use Get-WmiObject or Get-Package in PowerShell

You can use the “Get-WmiObject” or “Get-Package” in PowerShell to retrieve installed applications on a system. Combined with Uninstall() or Uninstall-Package. These commands allow you to script the removal of apps, even when the Control Panel uninstall option is unavailable.

Get-WmiObject -Class Win32_Product | Where-Object { $_.Name -like "*AppName*" } | ForEach-Object { $_.Uninstall() }

Alternatively, you could the “Get-Package” and you will have the desired result.

Get-Package -Name "*AppName*" | Uninstall-Package
uninstall package

As you can see above, the application has been uninstalled as shown above.

Please, see How to install Winget CLI on Windows, Install Applications with Winget CLI on Windows, and how Install SQL Server Management Studio 21 on Windows Server.

Use winget (if supported)

WinGet the Windows Package Manager that is available on Windows 11. It is also available on newer (modern) versions of Windows 10, and Windows Server 2025 as a part of the App Installer. The App Installer is a System Component delivered and updated by the Microsoft store on Windows Desktop versions, and via Updates on Windows Server 2025. If this is not case for you, please follow the steps below.

The WinGet command line tool is only supported on Windows 10 version 1809 (build 17763) or later. WinGet will not be available until you have logged into Windows as a user for the first time. Thereby, triggering Microsoft Store to register the Windows Package Manager as part of an asynchronous process.

Note: If you have recently logged in as a user for the first time and find that WinGet is not yet available. You can open PowerShell and enter the following command to request this WinGet registration according to Microsoft documentation: 

Add-AppxPackage -RegisterByFamilyName -MainPackage Microsoft.DesktopAppInstaller_8wekyb3d8bbwe
winget registration

Now, Winget is available and can be used to install and uninstall packages on your Windows device.

Winget option

Let us list the available applications on this device using the command below. This will reveal all the installed applications on the PC.

winget list
winget uninstall

Please, see Manage BitLocker and FileVault with Trellix Native Encryption, how to encrypt your system with Trellix Data Encryption, and how to Enable a Pre-Boot BitLocker PIN on Windows.

How to use Winget in Older Versions of Windows

To use winget in older versions of windows from PowerShell. You need to install the Microsoft.WinGet.Client module. Please, see How to keep Apps up to date on Windows devices. This article also discusses the steps to install winget.

Install winget

If you wish to use a preview version, please download the App Installer from here. Alternatively, you could navigate to the following URL.

App installer

Thereafter, you can start using the commands below or as described above to manipulate and uninstall applications on your device.

winget list
winget uninstall "App Name"

Please, see how to install and Manage Applications with Winget, how to install Winget on Windows Server, and how to In-place upgrade of Windows Server 2022 to 2025.

Use the App’s Own Uninstaller

Lastly, in this guide, you can check the installation folder path, such as “C:\Program Files\AppName\uninstall.exe” or “C:\Program Files (x86)\AppName\uninstall.exe”, and then run the uninstaller via Command Prompt or File Explorer.

cmd
"C:\Program Files\AppName\uninstall.exe" /S

FAQs

Why does MBAM show a machine as non-compliant even though BitLocker is enabled?

MBAM requires that BitLocker encryption is started through MBAM policy, not manually via Explorer or manage-bde. MBAM also checks that the recovery key is escrowed in its database. If the drive was encrypted outside of MBAM, the agent won’t recognise it as compliant especially when the same encryption algorithm is not used.

How can I make a non-compliant device compliant again?

To make a PC fully decrypt again, you can use the cmdlet to decrypt the drive “manage-bde -off“.
This ensures that the MBAM agent can correctly apply the configured MBAM GPO policies. Once the drive is decrypted, you can manually trigger BitLocker encryption through the MBAM client (mbamclientui.exe or mbamagent.exe /runpolicy). A reboot or running gpupdate /force can also help refresh policy. Finally, verify that the recovery key is successfully escrowed in MBAM. Once key escrow is confirmed, MBAM will report the system as compliant.

I hope you found this guide on “BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel” very useful. Please, feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Bitlocker, BitLocker behavior when MBAM agent is removed, BitLocker Drive Encryption Administration Utilities, BitLocker Key Recovery, BitLocker Recovery Keys, BitLocker Status, MBAM, MBAM for Bitlocker Administration, Microsoft BitLocker Administration and Monitoring, Microsoft BitLocker Administration and Monitoring (MBAM), Microsoft Windows, PowerShell, Windows 11, Windows Server 2016

Post navigation

Previous Post: Fix MSIEXEC returned 1602: Trellix Setup cannot use this account
Next Post: Full Integration Guide on how to Add Nutanix AHV to Veeam

Related Posts

  • Fix 0x800f0831 Windows Update
    Fix 0x800f0831 Error when installing Windows update Windows
  • image 81
    How to generate your trial SSL Certificate using DigiCert PKI platform Windows
  • How to Remove Language Pack
    How to forcefully remove Language Pack on Windows 10 and 11 Windows
  • mbamreports
    Email notifications for MBAM Enterprise and Compliance and Recovery Audit reports Windows
  • Featured image 2
    Microsoft Account Password Reset via Web and Windows Windows
  • ghm
    Single App Kiosk Mode Configuration using MDM Bridge WMI Provider Windows

More Related Articles

Fix 0x800f0831 Windows Update Fix 0x800f0831 Error when installing Windows update Windows
image 81 How to generate your trial SSL Certificate using DigiCert PKI platform Windows
How to Remove Language Pack How to forcefully remove Language Pack on Windows 10 and 11 Windows
mbamreports Email notifications for MBAM Enterprise and Compliance and Recovery Audit reports Windows
Featured image 2 Microsoft Account Password Reset via Web and Windows Windows
ghm Single App Kiosk Mode Configuration using MDM Bridge WMI Provider Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • sql
    How to alter a DATABASE compatibility level Oracle/MSSQL/MySQL
  • jhgfx
    How to make Cortana use your default web browser such as Google Chrome Windows
  • 1 8y62mmvjlr 5uovgoq6zmq
    How to download and install DriveLock on Windows Security | Vulnerability Scans and Assessment
  • Windows11
    How to change Regional Settings for all users on Windows 11 Windows
  • windows update 03
    Check if Windows Updates were installed via the Registry Editor Windows
  • Add or remove features   fix dotnet framework issues
    Fix the request to add or remove features on the specified server failed Windows
  • article 1280x720.13392821
    How to use command prompt to shutdown and restart your computer Windows
  • Prevent Local Administrators from turning off BitLocker 1
    Prevent Local Administrators from managing BitLocker with the manage-bde command Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,841 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.