Skip to content

Commit 7d7d1fd

Browse files
committed
Adding warning of potential conflict due to defualt configuration of the MDE Security Baseline
1 parent d3b33da commit 7d7d1fd

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

memdocs/intune/protect/encrypt-devices.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -175,9 +175,9 @@ Following are the relevant settings for each profile type:
175175
- **Compatible TPM startup key and PIN** - This setting must not be set to *Require startup key and PIN with TPM*
176176

177177
> ![WARNING]
178-
> While neither the endpoint security or device configuration policies configure the TPM settings by default, the [security baseline for Microsoft Defender for Endpoint](../protect/security-baselines.md#available-security-baselines) does configure both *Compatible TPM startup PIN* and *Compatible TPM startup key*, and might configure these settings in a way that blocks silent enablement of BitLocker.
178+
> While neither the endpoint security or device configuration policies configure the TPM settings by default, some versions of the [security baseline for Microsoft Defender for Endpoint](../protect/security-baselines.md#available-security-baselines) will configure both *Compatible TPM startup PIN* and *Compatible TPM startup key* by default. These configurations might block silent enablement of BitLocker.
179179
>
180-
> If you deploy this baseline to devices on which you want to silently enable BitLocker, review the baselines configuration for possible conflicts. To remove conflicts, either reconfigure the settings in the baseline to remove them, or remove applicable devices from receiving the baseline instances that configure the TPM settings that block silent enablement of BitLocker.
180+
> If you deploy this baseline to devices on which you want to silently enable BitLocker, review your baseline configurations for possible conflicts. To remove conflicts, either reconfigure the settings in the baselines to remove the conflict, or remove applicable devices from receiving the baseline instances that configure TPM settings that block silent enablement of BitLocker.
181181
182182
### View details for recovery keys
183183

0 commit comments

Comments
 (0)