Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy

A company is implementing a new security policy that requires all corporate-owned Windows 11 devices to automatically encrypt their hard drives using BitLocker. Devices are managed through Microsoft Intune. Which type of policy should be configured in Microsoft Intune to enforce this requirement?

  1. AApplication protection policy
  2. BConditional Access policy
  3. CDevice compliance policy
  4. DConfiguration profile
Show answer & explanation

Correct answer: D. Configuration profile

To directly configure device settings such as BitLocker encryption on corporate-owned devices, a device configuration profile is the appropriate choice in Microsoft Intune. This policy type allows administrators to deploy specific settings and features.

Why the other options are wrong

  • A. Application protection policies manage app-level data protection on personal or unmanaged devices, not device-level encryption.
  • B. Conditional Access policies control access to resources based on conditions, often leveraging compliance status, but they don't configure device settings.
  • C. Device compliance policies assess the health and security posture of a device, but they don't directly configure settings like BitLocker.

Intune Configuration Profile

A Microsoft Intune configuration profile is a container for settings that you can deploy to devices to configure features, security settings, Wi-Fi, VPN, email, and more.

  • Used to configure specific device settings.
  • Supports various platforms (Windows, iOS, Android, macOS).
  • Can enforce security features like BitLocker.

Memory trick: Configuring devices is like setting up a new phone, you need a profile for all the settings.

More Manage identity and compliance (10-15%) questions