## TL;DR
Run the encryption report in Intune admin center / Reports, filter to the not-encrypted and unknown devices, and export that short list. Most outliers turn out to be stale device records or machines missing the policy assignment, not actual unencrypted laptops. Fix the assignment, retire the stale records, and re-run the report after a check-in cycle until the list is clean.

## Steps
1. Intune admin center / Reports / Device compliance / Reports / open the encryption report. Expected: a per-device list with encryption state for the fleet.
2. Filter to Not encrypted and Unknown, then export to CSV for the audit trail. Expected: a short outlier list, not the whole fleet.
3. Triage each outlier: check whether the device is actually checking in (stale devices report as unknown) and whether the disk-encryption policy is assigned to it. Expected: most unknowns are stale records or missing assignments.
4. Remediate: assign the Endpoint security disk-encryption policy to the groups that are missing it, and retire stale device records so the report stays clean. Expected: after one check-in cycle the outlier list shrinks to named exceptions.
5. Save the exported CSV with the audit date alongside your compliance evidence. Expected: an auditor-ready file showing the fleet state on that date.

## Use this when
- You need a quarterly encryption-compliance audit for the fleet
- A new disk-encryption policy rolled out and you must prove coverage
- Leadership or an auditor asks what percentage of laptops are encrypted

## Not for this skill when
- A single user is locked out and needs a recovery key (per-device recovery flow)
- You are setting up the encryption policy itself rather than auditing it
- The devices are not Intune-managed (the report only covers enrolled devices)

## Compatibility
- Windows BitLocker and macOS FileVault via Intune disk-encryption policies
- Devices must be checking in; stale records show as unknown

## Variants
### Per-platform view
Split the report into Windows and macOS views when the two platforms have different policies or different exception lists.
### Encryption ready but not enforced
Some devices show the policy assigned but encryption not yet applied. Check the per-device policy status; the fix is usually a pending reboot or a check-in, not a new policy.

## Why it happens
The report reflects the last check-in state, not live disk state. Unknown almost always means the device has not reported recently, which is why triage starts with check-in freshness before assuming a laptop is actually unencrypted.

## Edge cases
- Personal and BYOD devices may legitimately be unencrypted. Scope the audit to corporate-owned devices so the report does not cry wolf.
- Dual-boot machines and unusual partition layouts can report encryption state incorrectly; hand-verify a sample before escalating.
- Keep a named exception list (lab machines, legacy hardware) so the same outliers do not get re-investigated every quarter.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_LCaVV-wa_ZGB7LSPXore8Q
