I'm new to Microsoft Bitlocker, currently we use McAfee to manage and encrypt our devices, however, the plan is to move all devices to Microsoft and manage them via Intune/MEM in a few months. I'm running into issues with Bitlcoker policies, they are not getting applied properly when applied from Intune/MEM.
Microsoft support is recommending that I should consider using a standalone "MBAM".
We have SCCM (Config manager) in place and our systems are co-managed. Our workload has been configured for Intune\MEM to manage "Endpoint protection".
Questions:
1) Should I use SCCM (config manager) just for "Bitlocker" and disable "Bitlocker" policy in Intune\MEM?
2) Manage "Bitlocker" policy from Intune\MEM only?
3) Setup a standalone MBAM to manage "Bitlcoker"?
Your help is much appreciated