What can IT admins do to prevent data leakage?
When a physical desktop isn’t secured properly, a company becomes exposed to a security incident if sensitive company data is leaked. In the previous chapter, we described how easy it is to store company data on a desktop. But what happens when a desktop is lost or, even worse, gets stolen? Bad actors can remove the disk drive from the endpoint and connect it to a different endpoint, gaining access to the data that is stored on the disk.
IT admins can use BitLocker, a disk encryption feature built into modern Windows versions to make sure that data cannot be read once the disk is attached to a different computer. IT admins can make use of a variety of tools to configure and maintain BitLocker on managed desktops, such as group policies or Microsoft Intune policies, by navigating to Endpoint security > Disk encryption.
Figure 2.6 – The location where IT admins create disk encryption policies...