Please can you update this as the GUI has since changed.
@MikeyGunit24 Жыл бұрын
Very helpful, thank you
@jamesa49582 жыл бұрын
Thank you
@sanjeev.bhardwaj11 ай бұрын
Hi all, There are two options available to encrypt drives: Option 01. under Endpoint Security > Disk Encryption and Option 02. through device configuration profiles. The requirements include saving the key to Azure AD and AD, with the need for silent encryption without a user interface. My question is, Q1. for SILENT BITLOCKER ENCRYPTION, which method should we choose, Option 01 or Option 02? Q2. If we create a profile only under Endpoint Security > Disk Encryption, will the encryption work? Q3. Or do we need to define BitLocker configuration in Endpoint Security, and use the same settings in the profile under device configuration? Q4. And same group assignment for profile created in option 1 and option 2.?
@JessieS3 жыл бұрын
I am a bit confused here, it seems you can also encrypt your devices with bitlocker using a configuration profile > Endpoint Security > Windows encryption Do different situations require different approaches?
@theCMC3 жыл бұрын
Hi Jessie sure you mean Config profile>Templates>Endpoint protection>windows encryption. Yes you can but that is the older way of doing it and the Endpoint Security>disk encryption is the latest approach within MEM as it is more focused. Saying that as per the video you can combine the too policies as required
@2Drezik Жыл бұрын
nice, thanks
@Loewie19842 жыл бұрын
Hi I hope you can help me with this, for days I have been trying to get Windows 11 pro to silent encrypt itself via intune device configuration policies, and all I have been getting is the following in the "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" log: "BitLocker CSP: GetDeviceEncryptionComplianceStatus indicates OSV is not compliant with returned status 0x2". When I configure the device to be encrypted, it prompts me. But when I configure "Hide prompt about third party encryption and "allow standard users to enable encryption during autopilot", seems like it breaks everything. Any suggestions? I knew that there's a difference between Windows Pro and Enterprise when writing keys back into Active Directory around Windows 7/8/8.1 era and, does this encryption only work during OOBE or also post log on, for lets say devices that are already deployed..
@MuslimWojak2 жыл бұрын
Whats the difference between this and endpoint security > Disk Encryption?
@theCMC2 жыл бұрын
Hi Foresyguy. In the video I am using Endpoint security > disk encryption. If you use the Config policy option using an endpoint protection template this gives you the ability to configure multiple security settings which includes BitLocker.
@foch412 жыл бұрын
After I setup Disc Encryption policy and its pushed out to all devices, will it automatically enable on all new devices added later?
@theCMC2 жыл бұрын
Foch41 hopefully you found the answer to this already but I believe as long as you say its assigned to all devices or a group you have assigned the policy to then yes.
@beikselect3 жыл бұрын
I don't know why I could not follow your movements when you explain. you give good knowledge but not clearto me how you getto this or that point. some how faster than it should be. but thankx for the effort appriciate your time :)