Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator is managing corporate-owned Windows 11 devices using Microsoft Intune. The organization requires that BitLocker encryption keys for these devices are automatically backed up to Azure Active Directory to ensure recovery in case of data loss or forgotten passwords. Which Intune policy setting enables this functionality?
- AWithin a 'Device restrictions' profile, configure 'Encryption' settings.
- BWithin a 'Compliance policy', set 'Require BitLocker' to 'Yes'.
- CWithin a 'Device features' profile, enable 'BitLocker drive encryption'.
- DWithin a 'Endpoint security > Disk encryption' profile, configure 'BitLocker recovery key storage'.
Show answer & explanationAnswer & explanation
Correct answer: D. Within a 'Endpoint security > Disk encryption' profile, configure 'BitLocker recovery key storage'.
Intune's 'Endpoint security > Disk encryption' profiles specifically manage BitLocker settings, including the crucial 'BitLocker recovery key storage' option, which allows for automatic backup of recovery keys to Azure AD.
Why the other options are wrong
- A. Device restrictions profiles offer basic encryption toggles but lack granular control over key storage.
- B. Compliance policies ensure BitLocker is enabled but do not configure how or where the recovery keys are stored.
- C. Device features profiles manage elements like notifications or device name, not encryption key escrow.
Intune BitLocker Key Escrow to Azure AD
A Microsoft Intune feature that automatically backs up BitLocker recovery keys for Windows devices to Azure Active Directory, enabling secure recovery by administrators or authorized users.
- Configured in Endpoint security > Disk encryption profiles.
- Ensures keys are available even if the device is lost or inaccessible.
- Improves data recovery and compliance for encrypted devices.
Memory trick: Key Escrow is like putting a 'spare key' in your Azure AD vault.