Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A company is implementing Microsoft Intune to manage its Windows 11 devices. The security team requires that all managed devices automatically encrypt their hard drives using BitLocker as soon as they enroll, without user interaction. Which Intune policy setting should you configure to meet this requirement?
- ADevices > Configuration profiles > Create profile > Windows 10 and later > Templates > Device restrictions > General > BitLocker: Allow and configure encryption.
- BEndpoint security > Disk encryption > BitLocker > Settings: Require device encryption, and configure encryption method.
- CEndpoint security > Security baselines > Windows 10 Security Baseline > BitLocker settings: Configure encryption method and require device encryption.
- DDevices > Windows > Configuration profiles > Create profile > Windows 10 and later > Settings catalog > Search for 'BitLocker' and configure relevant settings.
Show answer & explanationAnswer & explanation
Correct answer: B. Endpoint security > Disk encryption > BitLocker > Settings: Require device encryption, and configure encryption method.
To automatically enforce BitLocker encryption on enrolled devices without user interaction, the Endpoint security > Disk encryption policy in Intune is the most direct and effective method. This policy type is specifically designed for managing security features like BitLocker.
Why the other options are wrong
- A. While Device restrictions profiles can manage some BitLocker settings, the Endpoint security > Disk encryption profile offers more comprehensive and dedicated controls for BitLocker enforcement, especially for automatic, non-interactive encryption.
- C. Security baselines apply a set of recommended security configurations. While they include BitLocker settings, directly configuring a Disk encryption policy provides more granular control and ensures specific requirements are met beyond a baseline.
- D. The Settings catalog allows for granular configuration but requires searching for individual settings. The dedicated 'Disk encryption' profile provides a streamlined interface for common BitLocker deployment scenarios.
Intune Disk Encryption Policy
A Microsoft Intune policy type used to manage and enforce disk encryption technologies like BitLocker on Windows devices.
- Specifically designed for BitLocker and FileVault management.
- Allows for automatic deployment and enforcement of encryption.
- Found under 'Endpoint security' in the Intune admin center.
Memory trick: Encryption's Endpoint Shield: Direct, Secure, and Ready.