Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator is managing Windows 11 devices with Microsoft Intune. The organization has a strict policy requiring that all corporate data on devices, both at rest and in transit, must be encrypted. For data at rest, BitLocker is already configured via Intune. For data in transit, a VPN solution is in place. You need to verify the BitLocker recovery key escrow status for a specific device. Where would you find the BitLocker recovery key for an Intune-managed Windows 11 device?
- AIn the Azure Active Directory device object
- BIn the Intune Company Portal app on the device
- CIn the Microsoft 365 admin center
- DIn the device's local Active Directory object
Show answer & explanationAnswer & explanation
Correct answer: A. In the Azure Active Directory device object
For Intune-managed devices, BitLocker recovery keys are automatically escrowed to the device's object in Azure Active Directory (Azure AD). An administrator with appropriate permissions can retrieve these keys from the Azure AD portal.
Why the other options are wrong
- B. The Company Portal app is for user-facing actions and app installation, not for storing or retrieving administrator-level recovery keys.
- C. The Microsoft 365 admin center provides high-level management but detailed recovery keys are stored in Azure AD.
- D. This applies to devices joined to on-premises Active Directory, not typically Intune-managed Azure AD joined/hybrid joined devices.
Intune BitLocker Key Escrow
The process by which BitLocker recovery keys for Intune-managed devices are automatically backed up and stored securely in Azure Active Directory.
- Automated key storage.
- Keys stored in Azure AD device object.
- Requires appropriate Azure AD permissions to retrieve.
Memory trick: Azure AD holds the keys to the BitLocker kingdom for Intune devices.