How to configure/setup "Enable 'Require additional authentication at startup'" on Windows devices via Intune?

Vinod Survase 4,801 Reputation points
2023-06-12T14:12:19.77+00:00

How to configure/setup "Enable 'Require additional authentication at startup'" on Windows devices via Intune?

See below screenshots.

User's image

Microsoft Security | Intune | Security
Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Application management
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Crystal-MSFT 54,191 Reputation points Microsoft External Staff
    2023-06-13T01:59:42.8466667+00:00

    @Vinod Sur, Thanks for posting in Q&A. For the setting "Require additional authentication at startup'". Based on my researching, it will set

    "Configure TPM startup"

    "Configure TPM startup PIN"

    "Configure TPM startup key"

    "Configure TPM startup key and PIN"

    User's image

    https://www.prajwaldesai.com/enable-bitlocker-encryption-windows-10/

    Note: Non-Microsoft link, just for the reference.

    For such setting, in Intune, we can configure a similar setting named "Startup authentication required" under Endpoint security disk encryption policy or endpoint protection policy:

    User's image

    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#tpm-startup-pin-or-key

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


2 additional answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,426 Reputation points MVP
    2023-06-12T21:02:42.6233333+00:00

    You should find these settings under Endpoint Security \ Disk Encryption. If you will not manage this yourself, I could drop you a screenshot tomorrow of my Bitlocker settings which do cover this requirement.


  2. Pavel yannara Mirochnitchenko 13,426 Reputation points MVP
    2023-06-28T14:42:02.38+00:00

    Bitlocker-API is the key element here for troubleshoting (in Event Viewer). I suggest you open new thread because you already accepted the answer here. You can tag me in there then.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.