Glossary
BitLocker
BitLocker is the full disk encryption built into Windows. It scrambles everything on the drive so a stolen laptop gives up nothing without the right key, and it produces a recovery key that has to be stored somewhere safe, because without that key the data is gone for good.
How it works
BitLocker encrypts the volume with AES and keeps the key sealed inside the TPM chip on the motherboard. At boot, the TPM checks that the firmware and boot files have not been tampered with, releases the key, and Windows starts normally. The user sees nothing. Pull the SSD out and plug it into another machine and it is unreadable.
Then there is the recovery key, a 48 digit number Windows generates at setup. It is the fallback when the TPM refuses: a firmware update, a motherboard swap, a BIOS setting change. Consumer PCs push that key into the user's Microsoft account. In a company that is not good enough, and Microsoft has shipped MDM-based key escrow for exactly this reason. Since Windows 11 24H2, device encryption is enabled by default on far more new machines, which makes the escrow question urgent rather than optional.
Why it matters for a fleet
A laptop left in a taxi is an incident. An unencrypted laptop left in a taxi is a personal data breach you may have to notify within 72 hours under GDPR. Encryption is the cheapest control that turns one into the other, and it is the first thing an auditor asks to see evidence of.
Evidence is the word that matters. Telling an auditor the fleet is encrypted is an assertion. A report showing 312 of 318 Windows PCs with BitLocker active, and naming the six that are not, is proof. Those six are usually older machines with no TPM or a disabled one, and they are worth chasing individually.
The real-world risk is the recovery key, not the cipher. Teams that leave keys in users' personal Microsoft accounts eventually meet a machine nobody can unlock and an employee who has left.
How Appaloosa handles it
Appaloosa enforces BitLocker on enrolled Windows PCs through policy, reports encryption status per device, and stores the recovery key in the console so your helpdesk can unlock a machine without calling the former owner. Encryption state also feeds the compliance rules, so a PC that drops out of encryption can trigger a notification or lose access to managed apps. The Windows policies available are described on the Windows MDM page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo