How to configuring Disk Encryption Recovery Backup in Entra ID Using Endpoint Security Policy Template

Matthew Roll 0 Reputation points
2025-02-18T20:23:31.36+00:00

The policy template in Endpoint security | Disk encryption doesn’t provide an option to back up the recovery information in Entra ID instead of AD DS. It looks like the policy template has recently changed and is now missing the backup options to Entra ID. Could you please provide guidance on how to configure this with the current template using Intune?

Endpoint security | Disk encryption only list AD DS options:
User's image

Using a policy template -> Endpoint offer Entra ID options:

User's image

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
11,113 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,677 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Kancharla Saiteja 1,655 Reputation points Microsoft External Staff
    2025-02-24T12:09:35.81+00:00

    Hi @Matthew Roll ,

    Thank you for posting your query on Microsoft Q&A. I am Saiteja from Q&A will be assisting you with your query.

    Based on your query, I understand that you would like to enable the Disk encryption using Microsoft Intune and save it to Microsoft Entra ID.

    I believe this option comes up when you have enabled any GPO in your active directory to save the bit locker in your ADDS. This GPO generally configured using these steps: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption, Enable the policy Store BitLocker recovery information in Active Directory Domain Services (AD DS). You can disable the policy and follow our new documents of Microsoft Intune: https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices

    This is the newest documents and are the options currently available with Microsoft Intune. You can also find what's new in Microsoft Intune using this document: https://learn.microsoft.com/en-us/mem/intune/fundamentals/whats-new#new-disk-encryption-template-for-personal-data-encryption

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly "upvote it". If you have extra questions about this answer, please click "Comment".


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.