Centralized management of BitLocker drive encryption: The product (MBAM) provides an enterprise console and infrastructure to administer Windows BitLocker across all endpoints from one place, replacing per-machine manual configuration with policy-driven, organization-wide encryption management.
02
Enforcement of encryption policies across endpoints: Through Group Policy-integrated settings, administrators define and enforce which drives must be encrypted, the required encryption strength, and the conditions under which encryption is mandated, ensuring consistent protection across the estate.
03
Automated encryption of OS and data drives: Once policy is applied, the client agent automatically initiates and completes BitLocker encryption of operating-system and fixed data drives (and can require encryption of removable drives), removing the need for users to manually turn on encryption.
04
Recovery key escrow and centralized storage: As drives are encrypted, their BitLocker recovery keys and TPM owner information are automatically escrowed to a secured central database, so the organization always retains a way to recover access independent of the user.
05
Self-service recovery key retrieval portal: A self-service portal lets users who are locked out (for example after entering an incorrect PIN too many times) retrieve their own recovery key after identity verification, reducing help desk load for routine recovery events.
Your plan caps how many capabilities are shown — upgrade to see the full list