Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices are always encrypted with BitLocker and that the recovery keys are automatically backed up to Azure Active Directory (now Microsoft Entra ID). The administrator also needs to enforce a specific encryption strength (AES 256-bit). Which Intune Endpoint Security policy type should be configured?

  1. AAttack surface reduction policy
  2. BAccount protection policy
  3. CAntivirus policy
  4. DDisk encryption policy
Show answer & explanation

Correct answer: D. Disk encryption policy

The 'Disk encryption policy' within Intune's Endpoint security section is specifically designed for configuring BitLocker, enforcing encryption methods like AES 256-bit, and managing key escrow to Azure AD.

Why the other options are wrong

  • A. Attack surface reduction policies prevent certain behaviors or exploits, not disk encryption.
  • B. Account protection policies focus on user credentials and login security, not device-level disk encryption.
  • C. Antivirus policies manage malware protection, not disk encryption.

Intune Endpoint Security Disk Encryption

A policy type in Intune that manages device-level disk encryption (e.g., BitLocker for Windows), including encryption methods and recovery key storage.

  • Configures BitLocker settings for Windows devices.
  • Allows specifying encryption strength (e.g., AES 256-bit).
  • Includes options for automatic key escrow to Azure AD.

Memory trick: Disk Encryption for the whole drive, not just a file.

More Manage devices and apps (55-60%) questions