Michael Ulrich’s Post

View profile for Michael Ulrich, graphic

Systems Engineer at CBIZ | Passionate about Systems, Networking, Cloud, Operations, and Project Management

We have BitLocker! Microsoft's BitLocker is a security feature for the Windows operating system that provides drive encryption. This prevents data theft if the device is lost/stolen or tampered with in any way. The keys 😉 to success: ✔ The system receiving a BitLocker policy must have TPM 1.2 or later and Secure Boot must be enabled. (For a fuller list of reqs, see: https://lnkd.in/eRw9VGBq) 📜 We used an Endpoint Security Policy in Intune to set a basic BitLocker policy that silently deploys drive encryption. ❌ In our tests, the silent deployment failed because Secure Boot was disabled. After enabling in the UEFI settings, the encryption process kicked off silently at next boot without any user intervention. 🔐 The drive is now encrypting used space only and the recovery keys are backed up to the device object viewable in both Intune and Entra AD. 🔑 Onto configuring passwordless authentication! #Microsoft #LAPS #Entra #Intune #Autopilot #Cloud #Windows #PC #Azure #BitLocker #DriveEncryption

To view or add a comment, sign in

Explore topics