Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator is managing corporate-owned Windows 11 devices with Microsoft Intune. To enhance security, a policy needs to be implemented to ensure that all devices have BitLocker enabled, and their recovery keys are automatically backed up to Azure Active Directory. Which Intune policy type is best suited for this requirement?

  1. ADevice compliance policy
  2. BEndpoint security policy (Disk encryption)
  3. CDevice configuration profile (Custom OMA-URI)
  4. DSecurity baseline
Show answer & explanation

Correct answer: B. Endpoint security policy (Disk encryption)

Endpoint security policies, specifically the 'Disk encryption' profile, are purpose-built in Intune to configure BitLocker settings, including enabling encryption and escrowing recovery keys to Azure AD, offering a streamlined experience.

Why the other options are wrong

  • A. Compliance policies detect if BitLocker is enabled but don't configure it or escrow keys.
  • C. While possible, using OMA-URI for BitLocker is more complex and less intuitive than the dedicated Endpoint security policy.
  • D. Security baselines include BitLocker settings, but directly configuring an 'Endpoint security policy' provides more granular control for this specific requirement.

Intune Endpoint Security Disk Encryption

Intune Endpoint security policies, specifically the 'Disk encryption' profile type, provide a dedicated and simplified interface for configuring BitLocker on Windows devices, including recovery key escrow to Azure AD.

  • Dedicated policy type for BitLocker management.
  • Configures encryption, PIN/password requirements, and key escrow.
  • Streamlines deployment compared to custom profiles.

Memory trick: Endpoint Security: Encrypting Disks and Escrowing Keys.

More Manage devices and apps (55-60%) questions