> For the complete documentation index, see [llms.txt](https://docs.patchmypc.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.patchmypc.com/patch-my-pc-insights/dashboard-guides/advanced-insights-security-and-compliance-dashboard/advanced-insights-bitlocker-dashboard.md).

# Advanced Insights "BitLocker" Dashboard

BitLocker Drive Encryption data when integrated and managed by Endpoint Configuration Manager

*Applies to: Patch My PC Advanced Insights*

{% hint style="info" %}
The BitLocker dashboard requires the following hardware inventory classes to be enabled:

* BitLocker (Win32\_EncryptableVolume)
* BitLocker Encryption Details (Win32\_BitLockerEncryptionDetails)
* BitLocker Policy (Win32Reg\_MBAMPolicy)
* TPM (Win32\_TPM)
  {% endhint %}

For full functionality of this dashboard, MBAM should be integrated with ConfigMgr as outlined in this document:<https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/bitlocker/deploy-management-agent>

This will ensure the BitLocker Unmanaged and Recovery at Risk statistics are populated.

The top row of statistics help to identify where configuration errors may be causing compliance issues.

<figure><img src="https://3773699522-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MX7dvS0r_4fc0AikgJS%2Fuploads%2FZSQDiQ3vxi9Mw7Mwmg5g%2Fimage.png?alt=media&amp;token=bcc643ab-9d39-4748-8cf8-f75ade003d51" alt=""><figcaption><p>BitLocker compliance stats</p></figcaption></figure>

The first statistic, "BitLocker Unmanaged" shows Computers which have a BitLocker Encrypted Operating System Drive but are not under the control of a Configuration Manager or integrated MBAM Agent Management Policy. These devices may not conform to the required standard and will not report compliance.

Recovery at risk lists computers which have a BitLocker Encrypted Operating System Drive but have not yet escrowed a recovery key into the Configuration Manager database. You may be unable to access these devices in the event of a BitLocker Recovery prompt.

Inactive TPM portable devices lists laptops machines which do not show an activated TPM chip.

Non-Compliant Computers shows BitLocker Encrypted computers which do not conform to the BitLocker policies set in your environment. Clicking through will show the compliance conflicts:

<figure><img src="https://3773699522-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MX7dvS0r_4fc0AikgJS%2Fuploads%2FIbiRQ8Pmhsdzrc3u7Y7J%2Fimage.png?alt=media&amp;token=f8660b83-18e3-4690-a6e2-89b65d2c0095" alt=""><figcaption><p>Compliance failures</p></figcaption></figure>

The row of donut charts show the BitLocker status for all workstation clients (off, on, suspended or unknown). We show the BitLocker Cipher in use by the clients (this requires the MBAM integration listed above). We show the TPM version of the clients and the TPM Status (Activated, Enabled, Unknown). TPM "Enabled" is ready for activation by the OS, but is not currently in use.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.patchmypc.com/patch-my-pc-insights/dashboard-guides/advanced-insights-security-and-compliance-dashboard/advanced-insights-bitlocker-dashboard.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
