Configuring your BitLocker policy
Another important thing to consider is BitLocker drive encryption. While antivirus and firewall protect the machine when in use, this protects the data if your machine is lost or stolen. You should always use the strongest encryption possible and make it a requirement for device compliance and conditional access (more on those in Chapter 8).
There are specific settings for this policy to enable silent encryption during Autopilot, so you need to make sure these are set correctly.
How to do it…
The following steps will show you how to configure your BitLocker drive encryption policy:
- Within Endpoint security, click on Disk encryption and create a policy.
Set the policy’s Name and Description and click Next.
- Set the Base Settings values as per the following screenshot:
Figure 3.1 – BitLocker – Base Settings
- Set the Fixed Drive Settings values as per the following screenshot...