Linux encryption compliance policy

Alaa Elrayes 76 Reputation points
2024-03-10T12:41:43+00:00

Hello,

I created a compliance policy to check the encryption status on Linux device, my issue is we have Linux devices not encrypted with LUKS before installation.

As per this documentation, it is possible to encrypt Linux volumes after installation using encryptsetup tool.

encry

I searched for encryptsetup tool and I found that it is only encrypt Home folder. However, I followed up the instruction to encrypt Home folder but the device still non-compliant.

How to encrypt Linux devices without re-installation ?

Thanks,

Alaa Elrayes

Microsoft Intune Linux
Microsoft Intune Linux
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Linux: A family of open-source Unix-like operating systems.
42 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
137 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,371 questions
0 comments No comments
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 8,065 Reputation points Microsoft Vendor
    2024-03-11T05:53:05.1566667+00:00

    @Alaa Elrayes,Thanks for posting in Q&A.

    From your description, I know you want to encrypt Linux devices without re-installation to meet the compliance policy.

    Based on my research, if you already have Ubuntu installed without any encryption, then full disk encryption with LUKS may not be an option.

    And if you use the encryptsetup tool to only encrypt Home folder, but not encrypt the writable fixed disks on this computer, it may not meet the compliance policy settings. Therefore, it is suggested that you re-install the Linux devices and encrypt Linux devices during the installation to meet the compliance policy.

    Hopa above information can be helpful.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful