Skip to content

Commit f2a2bf1

Browse files
authored
Merge pull request #6721 from MicrosoftDocs/main
Publish 02/07/2022, 10:30 AM
2 parents 969a83a + 323901a commit f2a2bf1

2 files changed

Lines changed: 5 additions & 7 deletions

File tree

memdocs/cloud-native-windows-endpoints.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -404,6 +404,7 @@ Use Endpoint Security in Microsoft Endpoint Manager to configure encryption with
404404
- Check out our blog series on BitLocker at [Enabling BitLocker with Microsoft Endpoint Manager](https://techcommunity.microsoft.com/t5/intune-customer-success/enabling-bitlocker-with-microsoft-endpoint-manager-microsoft/ba-p/2149784).
405405

406406
These settings can be enabled in the [Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com) by going to **Endpoint Security** > **Disk encryption** > **Create Policy** > **Windows and later** > **Profile** = **BitLocker**.
407+
Configuring the BitLocker settings specified below will result in silenty enabling 128 bit encryption for standard users, which is one of the most common scenarios. However your organisation might have different security requirements, so consult the [BitLocker documentation](./intune/protect/encrypt-devices.md) for additional settings.
407408

408409
**BitLocker – Base Settings**:
409410

@@ -432,9 +433,9 @@ These settings can be enabled in the [Microsoft Endpoint Manager admin center](h
432433
- BitLocker system drive policy: **Configure**
433434
- Startup authentication required: **Yes**
434435
- Compatible TPM startup: **Required**
435-
- Compatible TPM startup PIN: **Not configured**
436-
- Compatible TPM startup key: **Not configured**
437-
- Compatible TPM startup key and PIN: **Not configured**
436+
- Compatible TPM startup PIN: **Block**
437+
- Compatible TPM startup key: **Block**
438+
- Compatible TPM startup key and PIN: **Block**
438439
- Disable BitLocker on devices where TPM is incompatible: **Not configured**
439440
- Enable preboot recovery message and url: **Not configured**
440441
- System drive recovery: **Configure**

memdocs/intune/protect/encrypt-devices.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -73,9 +73,6 @@ Use one of the following procedures to create the policy type you prefer.
7373

7474
4. On the **Configuration settings** page, configure settings for BitLocker to meet your business needs.
7575

76-
> [!TIP]
77-
> If you want to enable BitLocker silently, you must use a Endpoint protection template as part of a device configuration profile and not an Endpoint security policy. See [Silently enable BitLocker on devices](#silently-enable-bitlocker-on-devices) in this article for additional prerequisites and the specific setting configurations you must use.
78-
7976
Select **Next**.
8077

8178
5. On the **Scope (Tags)** page, choose **Select scope tags** to open the Select tags pane to assign scope tags to the profile.
@@ -252,4 +249,4 @@ For information about BitLocker deployments and requirements, see the [BitLocker
252249
- [Manage FileVault policy](../protect/encrypt-devices-filevault.md)
253250
- [Monitor disk encryption](../protect/encryption-monitor.md)
254251
- [Troubleshooting BitLocker policy](/troubleshoot/mem/intune/troubleshoot-bitlocker-policies)
255-
- [Known issues for Enforcing BitLocker policies with Intune](/windows/security/information-protection/bitlocker/ts-bitlocker-intune-issues)
252+
- [Known issues for Enforcing BitLocker policies with Intune](/windows/security/information-protection/bitlocker/ts-bitlocker-intune-issues)

0 commit comments

Comments
 (0)