Enable BitLocker with XTS-AES 256-bit encryption for stronger security
ID: 1c119d30-27d0-5919-9e7f-a0ba9e3a3068
STIX ID: report--1c119d30-27d0-5919-9e7f-a0ba9e3a3068
Feed Name: ThreatLocker Blog
This document provides a step-by-step guide to configure and enforce BitLocker Drive Encryption using Group Policy and Microsoft Intune, recommending XTS-AES 256 and full-disk encryption, TPM-only startup authentication, and storage of recovery information in AD DS while optionally restricting removable drives. It includes precise policy paths and settings for operating system and fixed data drives, guidance to pilot configurations, and instructions for recovering BitLocker keys via Intune and on-premises Active Directory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
