Configuring Disk Encryption Using Intune
Configuring Disk Encryption Using Intune
Summary
In this lab, you will configure BitLocker disk encryption using Intune.
Prerequisites
To following lab(s) must be completed before this lab:
0203-Manage Device Enrollment into Intune
0204-Enrolling devices into Intune
0301-Creating and Deploying Configuration Profiles
Note: You will also need a mobile phone that can receive text messages used to
secure Windows Hello sign in authentication to Entra ID.
Scenario
It's been determined that all the information on SEA-WS1 should be encrypted.
You've been asked to configure full disk encryption on SEA-WS1 and require
additional PIN authentication at startup.
Task 1: Configure device configuration policy in Intune
1. Sign in to SEA-SVR1 as Contoso\Administrator with the
password Pa55w.rd and close Server Manager.
2. On the taskbar, select Microsoft Edge.
3. In Microsoft Edge, type https://intune.microsoft.com in the address bar,
and then press Enter.
4. Sign in as as [email protected] with the default tenant
password.
5. In the Microsoft Intune admin center, select Endpoint security from the
navigation bar.
6. On the Endpoint security | Overview page, select Disk encryption.
7. On the Endpoint security | Disk encryption blade, in the details pane,
select Create Policy.
8. In the Create a profile page, select the following options, and then
select Create:
o Platform: Windows
o Profile: BitLocker
9. On the Basics page, enter the following information, and then select Next:
o Name: Contoso BitLocker
o Description: Enable BitLocker for all devices
10.On the Configurations settings tab, expand BitLocker and then configure
the following option:
o Require Device Encyrption: Enabled