iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To require BitLocker protection before users can write to removable USB drives, configure the Windows Endpoint security > Disk encryption policy in Microsoft Intune. The key setting makes unprotected removable data drives read-only; users can write to them after they are protected. Before rollout, account for the user setup step and confirm that your recovery and authentication choices comply with Microsoft’s documented policy constraints.
What Intune’s removable-drive policy controls
Intune’s Windows disk encryption policy includes settings for the encryption method used on removable data drives and for whether those drives must be BitLocker protected to allow write access. The setting documented as BitLocker - RemovableDrivesRequireEncryption blocks writes to removable drives unless BitLocker protection is active. A separate setting can restrict write access to drives configured in another organization. Check the available settings and labels in your tenant, as Microsoft’s admin-center interface can change. Microsoft’s Intune disk encryption settings reference describes the policy options.
The policy applies to removable data drives, including USB flash drives as a category. Microsoft’s documentation does not require a particular brand, model, capacity, or hardware-encryption feature.
What users experience when enforcement is enabled
Microsoft states that when the policy requiring BitLocker protection for write access is enabled, removable data drives without BitLocker protection are mounted read-only. A drive protected by BitLocker is mounted with read and write access. As a result, a user inserting an unprotected drive may need to complete BitLocker setup before saving files to it. Microsoft’s BitLocker configuration documentation describes this behavior.
#1 Best Overall
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
This is a practical trade-off: the policy limits writing data to unprotected removable media, but adds a setup step when users first need to write to a drive that does not yet meet the requirement. Communicate the expected workflow before enabling enforcement so users understand why a drive is read-only and what they must do to gain write access.
Choose enforcement, interoperability, and encryption settings
Use the policy choices to match the organization’s security requirements and day-to-day needs. The relevant decisions are:
- Write-access enforcement: Leave unencrypted removable drives writable, or require BitLocker protection so they are read-only until protected.
- Drive interoperability: Decide whether any BitLocker-protected drive may be writable or whether write access should be limited for drives configured by another organization. Consider how the restriction affects legitimate work across organizational boundaries.
- Encryption method: Select a supported method and strength for removable data drives. Microsoft documents AES 128-bit and AES 256-bit options in CBC or XTS modes; choose according to organizational requirements and verify the current values in Intune.
In Intune, open Endpoint security > Disk encryption and configure the Windows policy’s removable-drive options. Microsoft documents the settings as BitLocker - EncryptionMethodByDriveType for the removable-drive encryption method and BitLocker - RemovableDrivesRequireEncryption for write-access enforcement. Confirm the exact labels and options shown in your tenant before assigning the policy. Microsoft’s settings reference lists the documented configuration options.
Check recovery and authentication constraints before deployment
Do not enable the removable-drive write-access requirement without checking its interaction with your BitLocker recovery and authentication design. Microsoft’s BitLocker documentation says recovery keys must be disallowed when this policy is enabled. It also says TPM startup key and TPM key-and-PIN use must be disallowed under the policy. Confirm the applicable choices in the current Intune settings and Microsoft guidance, then ensure the organization’s recovery requirements can be met within those constraints. Microsoft’s BitLocker configuration documentation covers these interactions.
Rank #2
- FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
- Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
- Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
- New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
- Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed
Microsoft advises planning recovery before enabling BitLocker. Recovery planning should precede rollout rather than being treated as a follow-up task, particularly when the write-access policy limits recovery options.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Monitor encryption status and manage recovery keys
After deployment, use Intune’s encryption report to review encryption status across managed Windows devices and to view or manage recovery keys. Administrators need a role with the permissions required for those actions. Consult Microsoft’s Intune guidance for encrypting Windows devices with BitLocker for reporting, permissions, and recovery-planning details.
Use the report as an operational check after assigning the policy: review device encryption status and confirm administrators who handle recovery have the necessary access. Keep the recovery process aligned with the policy restrictions rather than assuming every standard BitLocker recovery option is compatible.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

