Encrypting MacOS Devices in Microsoft 365 E5: Configuration Guide

Encrypting MacOS Devices

Question

You have a Microsoft 365 subscription with Microsoft 365 E5 licenses, and manage your devices in Endpoint Manager.

Your devices consist of a mix of Windows 10 and MacOS devices.

You now want to encrypt your MacOS devices.

What should you configure?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

Correct Answer: D

FileVault is macOS's built-in disk encryption feature.

Encryption is done by using 128-bit AES encryption with a 256-bit key.

Configure FileVault by setting up an Endpoint Security - Disk encryption policy.

Microsoft Endpoint Manager admin center

« Home > Apps

A Home

Dashboard

= All services & Search (Ctrl+/) « + add v

5 Apps | App configuration policies

+ FAVORITES
© overview & Search by name
“ vevices All apps Name ty
Apps
HB App: Monitor Whizlabs app protection policy
© Endpoint security
By platform
Reports
I Windows
& users
Bh iosjipados
3S Groups
Gl macos
& Tenant administration
B android
2% Troubleshooting + support
Policy

‘App protection policies

App configuration policies

Option A is incorrect.

Bitlocker is used to encrypt Windows 10 Devices

Option B is incorrect.

Azure Storage Service Encryption used to encrypt Azure storage accounts ; Azure Blob storage and Azure file shares.

Option C is incorrect.

Always Encrypted is used for encrypting Azure SQL data.

To know more about encrypting MacOS, please refer to the link below:

The correct answer is D. FileVault.

Explanation: BitLocker is a Microsoft Windows feature used to encrypt hard drives on Windows devices. It is not available on macOS devices, so it cannot be used to encrypt your MacOS devices.

Azure Storage Service Encryption is a service provided by Microsoft Azure to encrypt data at rest stored in Azure Storage. This service cannot be used to encrypt your MacOS devices.

Always Encrypted is a feature provided in Microsoft SQL Server and Azure SQL Database to encrypt sensitive data at rest and in motion. It is not related to encrypting devices and cannot be used to encrypt your MacOS devices.

FileVault is a full-disk encryption feature provided by Apple in MacOS. It encrypts the entire hard drive on a MacOS device and is an effective way to protect data on a lost or stolen device. With FileVault enabled, the data on the hard drive is encrypted and can only be accessed by someone who has the correct password or recovery key. Therefore, to encrypt your MacOS devices, you should configure FileVault.

In conclusion, if you want to encrypt your MacOS devices, you should configure FileVault.