Question 1
A financial services company is implementing Microsoft Intune to manage its Windows 11 devices. The security team requires that all devices have BitLocker encryption enabled and that recovery keys are backed up to Microsoft Entra ID. However, a specific group of legacy accounting devices lacks a Trusted Platform Module (TPM) 2.0 chip. You need to create a compliance policy that enforces BitLocker but accommodates these legacy devices. Which configuration is required to achieve this?
Answer and explanation
Correct answer: B
Intune compliance policies for BitLocker do not automatically adapt for devices without a TPM. The best practice for this scenario is to create two distinct policies and use dynamic device groups to target them appropriately. One group can be created with a rule like (device.deviceTrustType -eq "TPM") for TPM-enabled devices, and another for devices without a TPM or with an older version. This ensures that all devices are evaluated for compliance correctly based on their hardware capabilities.