Bitlocker Encryption using Intune for On-Premise Machines, save keys in Azure AD, setup in 5 minutes

preview_player
Показать описание
In this video we will see what options we have for drive encryption and how to encrypt on-premise windows 10 machines using intune and enable drive encryption in minutes with no on-prem server set-up required.
Рекомендации по теме
Комментарии
Автор

Super helpful - thanks for creating and sharing this video!

sammysame
Автор

Nice! Used your instructions to setup Bitlocker.

damienhull
Автор

Hi,
In my case the computer shows this policy getting but the Encryption is not turning on and it status stays Bitlocker encryption off still, do i need to wait for some more time ?
Please note that my computers are not hybrid, just Cloud only.

iteepk
Автор

Hi, thanks a lot. Is there a way to make the PIN-Code mandatory? So the user has to set up a pin when logging into the machine the next time

flowryans
Автор

Hi Anubhav, your videos are very simple and informative. I am working on project where setup is hybrid and we enabled bitlocker from endpoint protection. We enabled option to store bitlocker protection keys in AAD. My AAD is not showing up these recovery keys for these devices. I went through many blogs and doc and it says that there is bug and we need to do it by powershell script. What are thoughts and suggestion here.

kbipan
Автор

Will this work if I have devices already encrypted? Will it export the recovery key?

Dylan-xkzg
Автор

Awesome video I have a hybrid environment and we are getting this up and running. is this true that the windows version has to be ultimate to do the encryption? Also can i have partitions?

MrBadlantern
Автор

QQ: How are you dealing with TPM on those VMs? Is it set by default when virtualizing?

ferlop
Автор

Is it a prerequisite to have Local machines either Hybrid or Azure AD joined ??

ravikaushik
Автор

Hi all,

There are two options available to encrypt drives:
Option 01. under Endpoint Security > Disk Encryption and

Option 02. through device configuration profiles.

The requirements include saving the key to Azure AD and AD, with the need for silent encryption without a user interface.

My question is,

Q1. for SILENT BITLOCKER ENCRYPTION, which method should we choose, Option 01 or Option 02?

Q2. If we create a profile only under Endpoint Security > Disk Encryption, will the encryption work?

Q3. Or do we need to define BitLocker configuration in Endpoint Security, and use the same settings in the profile under device configuration?

Q4. And same group assignment for profile created in option 1 and option 2.?

sanjeev.bhardwaj