Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot…

MITAuto-check passedBackend & APIs

Install Bitlocker Design

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-design --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bitlocker-design .claude/skills/bitlocker-design && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bitlocker-design
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
815 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot…

  • Works in 7 steps: Confirm prerequisites — TPM 2.0 (TPM 1.2… → Configure Intune disk encryption policy… → Silent enablement — Enable silently… → …
  • General Intune device management (use intune-device-mgmt)
  • SKILL.md covers When to use, Pick the configuration by…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bitlocker Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media. Covers compliance integration with Conditional Access and recovery workflows. WHEN: BitLocker, disk encryption, Windows encryption policy, BitLocker recovery key, silent BitLocker enablement, Intune disk encryption, TPM 2.0, escrow recovery key, encrypt…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Azure Key Vault, Microsoft Azure, Microsoft Entra ID and macOS. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • General Intune device management (use intune-device-mgmt)
  • Linux/macOS encryption (use intune-device-mgmt FileVault)
  • Azure disk encryption (use azure-key-vault)

Example prompts

  • “/bitlocker-design”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Confirm prerequisites — TPM 2.0 (TPM 1.2 in narrow cases), Secure Boot UEFI, supported
  2. Configure Intune disk encryption policy — Endpoint security → Disk encryption →
  3. Silent enablement — Enable silently enable BitLocker on devices and **escrow
  4. Verify recovery key escrow before broad rollout — Pull a pilot device's recovery key
  5. BitLocker To Go for removable drives — Separate policy: require password (8+ chars) or
  6. Feed compliance and Conditional Access — Add BitLocker / encryption to the Intune
  7. Monitor + recovery operations — Encryption report daily; alert on devices stuck at

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bitlocker Design loads about 1.9k tokens when it runs. Until then it costs about 199 tokens; SKILL.md has 815 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~199
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 815 words, ~1,901 tokens.

Download SKILL.mdSave it as .claude/skills/bitlocker-design/SKILL.md (or your agent's skills folder).
name
bitlocker-design
description
Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media. Covers compliance integration with Conditional Access and recovery workflows. WHEN: BitLocker, disk encryption, Windows encryption policy, BitLocker recovery key, silent BitLocker enablement, Intune disk encryption, TPM 2.0, escrow recovery key, encrypt endpoints, XTS-AES, BitLocker To Go, pre-boot authentication, removable drive encryption. DO NOT USE for general Intune device management (use intune-device-mgmt), Linux/macOS encryption (use intune-device-mgmt FileVault), or Azure disk encryption (use azure-key-vault).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

BitLocker Design

BitLocker provides full-volume encryption for Windows devices, protecting data at rest against device loss or theft. In cloud-managed estates it is deployed and monitored through Intune disk encryption endpoint security policies with recovery key escrow to Microsoft Entra ID.

When to use

Encrypting Windows endpoints and centrally managing recovery keys and compliance. Use this skill to choose pre-boot mode, configure silent enablement, and plan recovery before rollout.

Do not use this skill for general Intune device baseline (intune-device-mgmt), macOS FileVault (use Intune disk encryption policy directly), or Azure VM disk encryption (azure-key-vault).

Pick the configuration by device type

Device profilePre-boot authEncryptionNotes
Modern corporate laptop (TPM 2.0, Secure Boot)TPM-only (no PIN)XTS-AES 256Default; silent enable
High-sensitivity admin / Tier 0 (PAW)TPM + PINXTS-AES 256Stronger; pairs with PAW
Kiosk / unattendedTPM-only with Network UnlockXTS-AES 256No user to type PIN
Legacy device (no TPM 2.0 / no Secure Boot)Replace devicen/aDon't try to enable on bare-metal legacy
Removable media (USB)BitLocker To Go (password or smart card)XTS-AES 256Separate policy
Fixed data drivesAuto-unlock with OS driveXTS-AES 256Encrypt with OS drive

Rule of thumb: TPM-only + silent enablement is the right default for 95% of modern corporate laptops. TPM+PIN doubles the security against physical attack but triples support calls. Reserve TPM+PIN for Tier 0 / PAW.

Approach

  1. Confirm prerequisites — TPM 2.0 (TPM 1.2 in narrow cases), Secure Boot UEFI, supported Windows edition (Pro/Enterprise), Entra-joined or hybrid-joined (required for key escrow). Verify: Get-Tpm shows TpmReady=True; manage-bde -status shows the drive as encryptable.

  2. Configure Intune disk encryption policy — Endpoint security → Disk encryption → create a BitLocker profile. Set encryption method (XTS-AES 256), encrypt OS drive + fixed drives, pre-boot mode (TPM-only by default).

  3. Silent enablement — Enable silently enable BitLocker on devices and escrow recovery keys to Microsoft Entra ID automatically. User sees no prompt; encryption completes in background. This is the modern default. Verify: pilot device shows BitLocker = On, key escrowed to Entra (visible on device object), no user interaction recorded.

  4. Verify recovery key escrow before broad rollout — Pull a pilot device's recovery key from the Entra device blade. If you can't retrieve it, your policy is wrong - fix before scaling. Un-escrowed keys mean unrecoverable devices. Verify: 100% of pilot ring devices have key visible in Entra; help desk can retrieve.

  5. BitLocker To Go for removable drives — Separate policy: require password (8+ chars) or smart card for removable-drive encryption. Block writes to unencrypted removable drives via Defender for Endpoint device control if data sensitivity warrants.

  6. Feed compliance and Conditional Access — Add BitLocker / encryption to the Intune compliance policy. CA grant control "Require compliant device" then gates corporate apps on encryption status. Verify: an unencrypted device is reported non-compliant within the compliance grace period; blocked by CA.

  7. Monitor + recovery operations — Encryption report daily; alert on devices stuck at encrypting > 7 days. Document the help-desk recovery flow: user reads recovery key ID from boot screen → help desk looks up in Entra → reads back the key.

Show full SKILL.md (310 more words)Show less

Guardrails

  • Verify recovery key escrow is working before broad rollout - un-escrowed keys risk data loss. Pilot 50 devices, retrieve every key, then scale.
  • Pilot pre-boot authentication choices; they affect user experience and automation / imaging. TPM+PIN can break Wake-on-LAN, remote management, and unattended reboots.
  • Removable-drive encryption (BitLocker To Go) is a separate policy decision. Don't assume the OS-drive policy covers USB drives.
  • No TPM = no BitLocker (in practice). Software-only BitLocker is far weaker and a signal the device should be retired.
  • Recovery keys are sensitive. Help-desk procedure should require caller verification before reading a recovery key out loud.
  • Don't rotate recovery keys casually. Each rotation invalidates the escrowed key for a window; verify new escrow before treating the rotation as complete.

Common anti-patterns

  • "Enable BitLocker without verifying escrow" - First lost device, key missing, data unrecoverable. Verify escrow first.
  • "TPM+PIN for everyone" - 3x ticket volume on PIN-forgotten / PIN-locked. Reserve for PAW / Tier 0.
  • "Skip compliance integration" - Encrypted devices not surfaced to CA. Add to compliance policy.
  • "BitLocker To Go optional" - USB stick of customer data, unencrypted, lost = breach. Require for any device handling sensitive data.
  • "Help desk reads recovery key without verifying caller" - Social-engineering route to data theft. Verify identity.
  • "Encrypt then re-image without saving keys" - Easy to skip during refresh; re-images destroy recoverable state. Verify escrow before wiping.

Example prompts

  • Design a BitLocker policy with silent enablement via Intune and Entra escrow.
  • Set up TPM+PIN pre-boot authentication for our PAW devices.
  • Verify recovery key escrow on a pilot ring before broad rollout.
  • Configure BitLocker To Go for removable USB drives with password protection.
  • Add disk encryption to Intune compliance policy and gate Conditional Access.
  • Plan and document the help-desk recovery key workflow.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/bitlocker-design of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Bitlocker Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bitlocker Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bitlocker Design this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Releasing Blancbnfy/blanc114—~2.9kAutomated safety check: NotesMIT
Azure Key VaultMicrosoftDocs/Agent-Skills777—~4.9kAutomated safety check: PassCC-BY-4.0
Agent Notifications777genius/agent-notifications816—~1.8kAutomated safety check: PassCustom licence

Similar skills

  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Releasing Blanc

    bnfy/blanc

    Full runbook for cutting a Blanc desktop release — scripts/release.sh mechanics and its required BLANCRELEASE env vars, macOS notarization via 1Password, the Touch ID provisioning profile and…

    114 GitHub stars~2.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Azure Key Vault

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Key Vault development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations &…

    777 GitHub stars~4.9k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Agent Notifications

    777genius/agent-notifications

    Send an Agent Notifications desktop notification when the user requests one, attention is needed, or a meaningful milestone warrants an alert during ongoing work.

    816 GitHub stars~1.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Subspace Builds

    dallison/subspace

    Build and test Subspace across supported platforms and build systems.

    104 GitHub stars~990 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Bitlocker Design

What does Bitlocker Design do?

Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot…. Bitlocker Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media.

When should I use Bitlocker Design?

Bitlocker Design fits situations like: general Intune device management (use intune-device-mgmt); linux/macOS encryption (use intune-device-mgmt FileVault); azure disk encryption (use azure-key-vault).

How do I install Bitlocker Design in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a claude-code`. Or copy the skill folder (skills/bitlocker-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/bitlocker-design in your project. Claude Code loads it when a task matches its description.

How do I install Bitlocker Design in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a codex`. Or copy the skill folder (skills/bitlocker-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/bitlocker-design in your project. Codex loads it when a task matches its description.

Can I use Bitlocker Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bitlocker-design, .gemini/skills/bitlocker-design, .github/skills/bitlocker-design and .opencode/skills/bitlocker-design in your project.

What does Bitlocker Design need to run?

SKILL.md names no scripts, command-line tools or credentials: Bitlocker Design is instructions for the agent only.

Does Bitlocker Design access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Bitlocker Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bitlocker Design use?

Bitlocker Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bitlocker Design use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bitlocker Design?

Skills that share tags, products or a category with Bitlocker Design: Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars), Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Releasing Blanc (bnfy/blanc, 114 stars) and Azure Key Vault (MicrosoftDocs/Agent-Skills, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bitlocker Design?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.