Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices have BitLocker enabled, with recovery keys automatically escrowed to Azure Active Directory. Users should not be prompted for BitLocker setup. Which Intune policy type should be configured?
- AEndpoint security > Disk encryption
- BUpdate rings for Windows 10 and later
- CDevice configuration > Windows 10 and later > Endpoint protection
- DDevice restrictions > Windows 10 and later
Show answer & explanationAnswer & explanation
Correct answer: A. Endpoint security > Disk encryption
The 'Endpoint security > Disk encryption' policy in Intune is specifically designed for configuring BitLocker on Windows devices, including settings for encryption, recovery key escrow to Azure AD, and user experience during setup.
Why the other options are wrong
- B. Update rings manage Windows updates and have no relevance to disk encryption.
- C. While 'Endpoint protection' in device configuration profiles has some security settings, the dedicated 'Disk encryption' policy under Endpoint security is more comprehensive for BitLocker.
- D. Device restrictions profiles control various device functionalities but are not the primary place for detailed BitLocker configuration and key escrow.
Intune BitLocker Policy
A Microsoft Intune policy under Endpoint Security used to manage BitLocker Drive Encryption on Windows devices, including encryption settings and recovery key escrow.
- Enables BitLocker on OS drives and fixed/removable data drives.
- Automatically escrows recovery keys to Azure AD for easy retrieval.
- Can configure user interaction during setup.
Memory trick: Disk Encryption Secures Keys Automatically.