Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator is configuring a new corporate-owned Windows 11 device. The device will be Azure AD joined and automatically enrolled into Microsoft Intune. The administrator needs to ensure that the device's BitLocker recovery keys are automatically backed up to Azure AD. Which configuration within Intune is necessary to achieve this?

  1. AConfigure a Custom OMA-URI profile to enable BitLocker key escrow.
  2. BConfigure an Endpoint Security Disk encryption profile for BitLocker.
  3. CConfigure a Device Restriction profile to enable BitLocker.
  4. DConfigure a Windows Update ring to enforce BitLocker.
Show answer & explanation

Correct answer: B. Configure an Endpoint Security Disk encryption profile for BitLocker.

Microsoft Intune offers dedicated Endpoint Security Disk encryption profiles specifically for managing BitLocker settings, including the automatic escrow of recovery keys to Azure AD. This is the most direct and recommended method.

Why the other options are wrong

  • A. While OMA-URI can configure many settings, there is a native Intune profile for BitLocker key escrow, making OMA-URI unnecessary and more complex.
  • C. Device Restriction profiles have some BitLocker settings, but the Endpoint Security profile is more comprehensive and designed for key escrow.
  • D. Windows Update rings manage update behavior, not disk encryption or key escrow.

Intune Endpoint Security BitLocker

Using Microsoft Intune's Endpoint Security Disk encryption profile to manage BitLocker settings, including automatic recovery key escrow to Azure AD.

  • Dedicated profile for disk encryption.
  • Ensures recovery keys are safely stored in Azure AD.
  • Applies to Windows 10/11 devices.

Memory trick: Endpoint Security 'secures' your BitLocker keys.

More Manage devices and apps (55-60%) questions