
Source: https://docs.microsoft.com/en-us/intune/protect/compliance-policy-create-windows

Require BitLocker
Create Policy
Name: Win10 | Require BitLocker
Select: Windows 10 and later
Device Health > Require BitLocker > Require

Actions for noncompliance
Action: Send email to end user
Message template: Notification message templates
Additional recipients: Maybe IT support
Schedule (days after noncompliance): 7

For Windows devices the “Remotely lock the noncompliant device” options does not work.

Set “Schedule (days after noncompliance)” higer then 0 (zero) because you regularly get false / positive results. Intune has a long processing time.