Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard

A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. A new security policy dictates that all devices must have BitLocker enabled, and their recovery keys must be escrowed to Azure Active Directory for administrative access and recovery purposes. Which Intune policy setting should be configured to ensure BitLocker recovery keys are stored in Azure AD?

  1. AEndpoint security > Disk Encryption > BitLocker > Recovery key escrow > Allow standard users to save BitLocker recovery keys to Azure AD
  2. BDevices > Configuration profiles > Windows 10 and later > Endpoint protection > Windows Encryption > Store recovery information in Azure Active Directory
  3. CDevices > Compliance policies > Windows 10 and later > Device Health > Require BitLocker
  4. DEndpoint security > Disk Encryption > BitLocker > Recovery key escrow > Configure BitLocker recovery key escrow
Show answer & explanation

Correct answer: B. Devices > Configuration profiles > Windows 10 and later > Endpoint protection > Windows Encryption > Store recovery information in Azure Active Directory

While 'Endpoint security > Disk Encryption' is a more modern blade, the specific setting for escrowing BitLocker recovery keys to Azure AD is found under 'Devices > Configuration profiles > Windows 10 and later > Endpoint protection > Windows Encryption > Store recovery information in Azure Active Directory'. This setting directly controls the storage of recovery keys in Azure AD.

Why the other options are wrong

  • A. This setting is about allowing standard users to save keys, not the primary administrative configuration for escrowing keys to Azure AD.
  • C. A compliance policy only reports if BitLocker is enabled; it does not configure or enforce the escrow of recovery keys to Azure AD.
  • D. This option is too generic; the specific setting for Azure AD escrow is more granular and found in a different section than just a general 'Configure BitLocker recovery key escrow'.

Intune BitLocker Key Escrow to Azure AD

The process of configuring Microsoft Intune to automatically store BitLocker recovery keys for Windows devices in Azure Active Directory, allowing administrators to retrieve them for device recovery.

  • Crucial for device recovery and administrative access.
  • Configured via 'Configuration profiles' in Intune.
  • Specific setting: 'Store recovery information in Azure Active Directory'.
  • Ensures keys are securely accessible by authorized personnel.

Memory trick: Keys ascend to Azure AD for safe keeping.

More Manage devices and apps (55-60%) questions