Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard
A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. To ensure data protection, BitLocker is enabled on all devices, and the recovery keys are required to be stored securely in Azure Active Directory. During an audit, it was discovered that some devices are not escrowing their keys. Which specific location in Azure AD should the administrator check to verify if a device's BitLocker recovery key has been successfully escrowed?
- AAzure AD > Users > All users > Select a user > Devices.
- BAzure AD > Devices > All devices > Select a device > Recovery keys.
- CAzure AD > Enterprise applications > All applications > Microsoft Intune > Users and groups.
- DAzure AD > Devices > All devices > Device properties > Diagnostics.
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD > Devices > All devices > Select a device > Recovery keys.
To verify if a BitLocker recovery key has been successfully escrowed to Azure AD for a specific device, the administrator should navigate to 'Azure AD > Devices > All devices', select the target device, and then choose the 'Recovery keys' blade. This section directly displays any escrowed BitLocker keys.
Why the other options are wrong
- A. While a user owns devices, the recovery keys are associated with the device object itself, not directly under the user's properties.
- C. This path is for managing Intune application access, not for viewing BitLocker recovery keys.
- D. Diagnostics provide general device information, not BitLocker recovery keys.
Azure AD BitLocker Key Escrow Location
BitLocker recovery keys for Azure AD-joined or Hybrid Azure AD-joined devices are automatically escrowed and stored securely within the device object in Azure Active Directory, accessible via the Azure portal.
- Keys are stored under the device object in Azure AD.
- Accessible by users with appropriate permissions (e.g., Cloud Device Administrator).
- Crucial for data recovery if a device is locked out.
Memory trick: Device's Keys: Find them with the Device, not the User.