Encryption shall be required on all devices
Last updated
Last updated
Disk encryption shall be configured on all corporate owned devices. Encryption of corporate data should also be configured at an application layer where applicable. In the Endpoint Manager Admin center, there is multiple locations to configure device encryption:
Endpoint Security>Disk Encryption: Allows you to configure encryption settings for FileVault (macOS) and Bitlocker (Windows).
Configuration Profiles: Endpoint Protection (Windows Encryption, FileVault), Device Restrictions (iOS, Android)
App Protection Policies (For application data encryption): iOS and Android
Disk encryption shall be required on all devices
β’ Any tenant with Intune licensing can access this setting.
Disk Encryption:
Configuration Profiles:
App Protection Policies:
If configured correctly, the end user should have no interaction with configuring encryption on the device. Leveraging configuration profiles or disk encryption settings should automatically configure the device encryption. There could be a use case where the configuration fails and the end user is prompted to fix on their device.
None Currently