Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices with Microsoft Intune. To enhance security, the administrator needs to ensure that BitLocker encryption keys are automatically escrowed to Azure Active Directory (now Microsoft Entra ID) for recovery purposes. Which Intune profile type should be configured?

  1. ADevice configuration profile (Custom OMA-URI)
  2. BWindows Update ring
  3. CApp protection policy
  4. DEndpoint security Disk encryption
Show answer & explanation

Correct answer: D. Endpoint security Disk encryption

BitLocker key escrow to Azure AD is a core function of disk encryption management, which is specifically handled by the 'Endpoint security Disk encryption' profile type in Intune.

Why the other options are wrong

  • A. While OMA-URI can configure many settings, there's a dedicated profile for disk encryption, which is preferred.
  • B. Windows Update rings manage update deployment, not disk encryption.
  • C. App protection policies manage data within applications, not device-level disk encryption.

Intune BitLocker Key Escrow

The process of securely storing BitLocker recovery keys in Azure Active Directory (now Microsoft Entra ID) to allow administrators or users to recover encrypted drives.

  • Managed through Intune's 'Endpoint security Disk encryption' profile.
  • Ensures keys are accessible for recovery even if the user forgets their password.
  • Crucial for data recovery and compliance.

Memory trick: Disk encryption secures keys, Endpoint Security helps retrieve.

More Manage devices and apps (55-60%) questions