To rotate BitLocker keys in Microsoft Intune, you will need to have the Intune Administrator position assigned if you’re utilizing the Microsoft Intune admin portal.
Or, if you want to programmatically rotate BitLocker keys utilizing Microsoft Graph, then you definitely additionally must consent to the DeviceManagementManagedDevices.ReadWrite.All permission with a International Administrator and have the Beta Microsoft Graph PowerShell SDK put in. For bulk rotating BitLocker keys, additionally, you will must consent to the DeviceManagementConfiguration.Learn.All permission to learn the encryption standing of every machine.