Skip to content

Commit 824b9fa

Browse files
authored
Merge pull request #16460 from MicrosoftDocs/main
publish main to live, 10/25/24, 3:30 pm
2 parents ac693df + cc89020 commit 824b9fa

File tree

4 files changed

+67
-66
lines changed

4 files changed

+67
-66
lines changed

memdocs/intune/protect/encrypt-devices-filevault.md

Lines changed: 62 additions & 61 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,18 @@
11
---
22
# required metadata
3-
title: Encrypt macOS devices with FileVault disk encryption with Intune
3+
title: Encrypt macOS FileVault disk encryption with Intune policy
44
titleSuffix: Microsoft Intune
5-
description: Use Microsoft Intune encryption policy to encrypt macOS devices with FileVault, and manage recovery keys for encrypted macOS devices from within the Microsoft Intune admin center.
5+
description: Use Microsoft Intune policy to configure FileVault on macOS devices, and use the admin center to manage their recovery keys.
66
keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 06/21/2024
10+
ms.date: 10/25/2024
1111
ms.topic: how-to
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
1414
ms.localizationpriority: high
15-
ms.assetid:
15+
ms.assetid:
1616

1717
# optional metadata
1818

@@ -30,7 +30,7 @@ ms.collection:
3030

3131
---
3232

33-
# Use FileVault disk encryption for macOS with Intune
33+
# Use FileVault disk encryption for macOS with Intune
3434

3535
Use Microsoft Intune to configure and manage macOS FileVault disk encryption. FileVault is a whole-disk encryption program that is included with macOS. With Intune you can deploy policies that configure FileVault, and then manage recovery keys on devices that run **macOS 10.13 or later**.
3636

@@ -66,62 +66,18 @@ You can add this permission and right to your own [custom RBAC roles](../fundame
6666
- Help Desk Operator
6767
- Endpoint Security Administrator
6868

69-
## Create device configuration policy for FileVault
70-
71-
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
72-
73-
2. Select **Devices** > **Manage devices** > **Configuration** > On the *Policies* tab, select **+ Create**.
74-
75-
3. On the **Create a profile** page, set the following options, and then select **Create**:
76-
- **Platform**: macOS
77-
- **Profile type**: Templates
78-
- **Template name**: Endpoint protection
79-
80-
:::image type="content" source="./media/encrypt-devices-filevault/select-macos-filevault-dc.png" alt-text="Select the Endpoint protection profile.":::
81-
82-
4. On the **Basics** page, enter the following properties:
83-
84-
- **Name**: Enter a descriptive name for the policy. Name your policies so you can easily identify them later. For example, a good policy name might include the profile type and platform.
85-
86-
- **Description**: Enter a description for the policy. This setting is optional, but recommended.
87-
88-
5. On the **Configuration settings** page, select **FileVault** to expand the available settings:
89-
90-
:::image type="content" source="./media/encrypt-devices-filevault/filevault-settings.png" alt-text="FileVault settings.":::
91-
92-
6. Configure the following settings:
93-
94-
- For *Enable FileVault*, select **Yes**.
95-
96-
- For *Recovery key type*, select **Personal key**.
97-
98-
- For *Escrow location description of personal recovery key*, add a message to help guide users on [how to retrieve the recovery key](#retrieve-a-personal-recovery-key) for their device. This information can be useful for your users when you use the setting for Personal recovery key rotation, which can automatically generate a new recovery key for a device periodically.
99-
100-
For example: To retrieve a lost or recently rotated recovery key, sign in to the Intune Company Portal website from any device. In the portal, go to *Devices* and select the device that has FileVault enabled, and then select *Get recovery key*. The current recovery key is displayed.
101-
102-
Configure the remaining [FileVault settings](endpoint-protection-macos.md#filevault) to meet your business needs, and then select **Next**.
103-
104-
7. If applicable, on the **Scope (Tags)** page, choose **Select scope tags** to open the Select tags pane to assign scope tags to the profile.
105-
106-
Select **Next** to continue.
107-
108-
8. On the **Assignments** page, select groups to receive this profile. For more information on assigning profiles, see Assign user and device profiles.
109-
Select **Next**.
110-
111-
9. On the **Review + create** page, when you're done, choose **Create**. The new profile is displayed in the list when you select the policy type for the profile you created.
112-
11369
## Create endpoint security policy for FileVault
11470

11571
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
11672

11773
2. Select **Endpoint security** > **Disk encryption** > **Create Policy**.
11874

119-
1. On the **Basics** page, enter the following properties, and then choose **Next**.
120-
- **Platform**: macOS
121-
- **Profile**: FileVault
75+
3. On the **Basics** page, enter the following properties, and then choose **Next**.
76+
- **Platform**: macOS
77+
- **Profile**: FileVault
12278

12379
![Select the FileVault profile](./media/encrypt-devices-filevault/select-macos-filevault-es.png)
124-
80+
12581
4. On the **Configuration settings** page:
12682
1. Set *Enable FileVault* to **Yes**.
12783
2. For *Recovery key type*, only **Personal Recovery Key** is supported.
@@ -172,7 +128,7 @@ Select **Next**.
172128

173129
7. If applicable, on the **Scope (Tags)** page, choose **Select scope tags** to open the *Select tags* pane to assign scope tags to the profile. Select **Next** to continue.
174130

175-
8. On the **Assignments** page, select the groups that will receive this profile. For more information on assigning profiles, see Assign user and device profiles. Select **Next**.
131+
8. On the **Assignments** page, select the groups that receive this profile. For more information on assigning profiles, see Assign user and device profiles. Select **Next**.
176132

177133
9. On the **Review + create** page, when you're done, select **Create**. The new profile is displayed in the list when you select the policy type for the profile you created.
178134

@@ -187,16 +143,61 @@ For devices that run macOS 14 and later, your settings catalog policy can also e
187143
- When *Await final Configuration* set to *Yes* for a device, you can then add the following Full Disk Encryption setting for FileVault in your settings catalog profile
188144

189145
- FileVault > **Force Enable in Setup Assistant** – Set to **Enabled**.
190-
146+
191147
The following image shows the settings catalog profile configured with the core settings to enable FileVault and use the Setup Assistant to enforce encryption. In this example, the Location setting uses the simple name of our domain, *Contoso*:
192148

193-
194-
195149
> [!IMPORTANT]
196150
> The **Defer** setting must be configured to **Enabled** to successfully enable FileVault in Setup Assistant for devices running macOS 14.4.
197-
151+
198152
:::image type="content" source="./media/encrypt-devices-filevault/filevault-setup-assistant-configuration.png" alt-text="Screenshot of the settings needed to enable File Vault in Setup Assistant.":::
199153

154+
## Create device configuration policy for FileVault (Deprecated)
155+
156+
> [!NOTE]
157+
> The macOS template for Endpoint Protection is deprecated and no longer supports creating new profiles. Instead, use the [Endpoint security](#create-endpoint-security-policy-for-filevault) or the [settings catalog](#create-settings-catalog-policy-for-filevault) to configure and manage new FileVault profiles.
158+
159+
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
160+
161+
2. Select **Devices** > **Manage devices** > **Configuration** > On the *Policies* tab, select **+ Create**.
162+
163+
3. On the **Create a profile** page, set the following options, and then select **Create** > **New policy**:
164+
- **Platform**: macOS
165+
- **Profile type**: Templates
166+
- **Template name**: Endpoint protection (Deprecated)
167+
168+
:::image type="content" source="./media/encrypt-devices-filevault/select-macos-filevault-dc.png" alt-text="Screen shot that displays the the Endpoint protection profile.":::
169+
170+
4. On the **Basics** page, enter the following properties:
171+
172+
- **Name**: Enter a descriptive name for the policy. Name your policies so you can easily identify them later. For example, a good policy name might include the profile type and platform.
173+
174+
- **Description**: Enter a description for the policy. This setting is optional, but recommended.
175+
176+
5. On the **Configuration settings** page, select **FileVault** to expand the available settings:
177+
178+
:::image type="content" source="./media/encrypt-devices-filevault/filevault-settings.png" alt-text="Screen shot that displays FileVault settings.":::
179+
180+
6. Configure the following settings:
181+
182+
- For *Enable FileVault*, select **Yes**.
183+
184+
- For *Recovery key type*, select **Personal key**.
185+
186+
- For *Escrow location description of personal recovery key*, add a message to help guide users on [how to retrieve the recovery key](#retrieve-a-personal-recovery-key) for their device. This information can be useful for your users when you use the setting for Personal recovery key rotation, which can automatically generate a new recovery key for a device periodically.
187+
188+
For example: To retrieve a lost or recently rotated recovery key, sign in to the Intune Company Portal website from any device. In the portal, go to *Devices* and select the device that has FileVault enabled, and then select *Get recovery key*. The current recovery key is displayed.
189+
190+
Configure the remaining [FileVault settings](endpoint-protection-macos.md#filevault) to meet your business needs, and then select **Next**.
191+
192+
7. If applicable, on the **Scope (Tags)** page, choose **Select scope tags** to open the Select tags pane to assign scope tags to the profile.
193+
194+
Select **Next** to continue.
195+
196+
8. On the **Assignments** page, select groups to receive this profile. For more information on assigning profiles, see Assign user and device profiles.
197+
Select **Next**.
198+
199+
9. On the **Review + create** page, when you're done, choose **Create**. The new profile is displayed in the list when you select the policy type for the profile you created.
200+
200201
## Manage FileVault
201202

202203
To view information about devices that receive FileVault policy, see [Monitor disk encryption](../protect/encryption-monitor.md).
@@ -224,7 +225,7 @@ Intune can’t manage FileVault disk encryption on a macOS device that is encryp
224225
- [Upload a personal recovery key to Intune](#upload-a-personal-recovery-key) – Use this method when the user knows their personal recovery key.
225226
- [The user generates a new recovery key on the device](#generate-a-new-recovery-key-on-the-device) – Use this method if the personal recovery key isn’t known by the user.
226227

227-
Both methods require that the device has active policy from Intune that manages FileVault encryption. To deliver this policy, you can use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), or a [device configuration endpoint protection profile](#create-device-configuration-policy-for-filevault) to encrypt devices with FileVault.
228+
Both methods require that the device has active policy from Intune that manages FileVault encryption. To deliver this policy, use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault).
228229

229230
#### Upload a personal recovery key
230231

@@ -238,7 +239,7 @@ Upon upload, Intune rotates the key to create a new personal recovery key. Intun
238239

239240
Before Intune can assume management of encryption of a user-encrypted device, that device must receive an Intune FileVault policy for disk encryption.
240241

241-
Use either an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), or a [device configuration endpoint protection profile](#create-device-configuration-policy-for-filevault) to encrypt devices with FileVault.
242+
Use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), to encrypt devices with FileVault.
242243

243244
- **The user who encrypted the device must have access to their personal recovery key for the device and be directed to upload it to Intune.**
244245

@@ -271,7 +272,7 @@ To enable Intune to manage FileVault on a previously encrypted device, the user
271272

272273
Before Intune can assume management of encryption of a user-encrypted device, that device must receive an Intune FileVault policy for disk encryption.
273274

274-
Use either an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), or a [device configuration endpoint protection profile](#create-device-configuration-policy-for-filevault) to encrypt devices with FileVault.
275+
Use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault) to encrypt devices with FileVault.
275276

276277
- **The device user must have access to the Terminal app on the encrypted device.**
277278

memdocs/intune/protect/endpoint-protection-macos.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: lenewsad
88
ms.author: lanewsad
99
manager: dougeby
10-
ms.date: 08/15/2022
10+
ms.date: 10/25/2024
1111
ms.topic: reference
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -32,7 +32,9 @@ ms.collection:
3232
# macOS endpoint protection settings in Intune
3333

3434
> [!IMPORTANT]
35-
> The macOS endpoint protection template has been deprecated. Existing policies remain unchanged, but you can no longer create new policies using this template. We recommend using the settings catalog to create new configuration policies for FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. For more information, see [macOS settings catalog](../configuration/settings-catalog.md).
35+
> The macOS endpoint protection template has been deprecated. Existing policies remain unchanged, but you can no longer create new policies using this template. > Instead, use one of the following options:
36+
> - Use Endpoint security policies like [disk encryption](../protect/endpoint-security-disk-encryption-policy.md) for Filevault, or [Firewall](../protect/endpoint-security-firewall-policy.md) policy.
37+
> - Use the Settings catalog to create new configuration policies for FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. For more information, see [macOS settings catalog](../configuration/settings-catalog.md).
3638
3739
This article shows you the endpoint protection settings that you can configure for devices that run macOS. You configure these settings by using a macOS device configuration profile for [endpoint protection](endpoint-protection-configure.md) in Intune.
3840

16 KB
Loading

windows-365/enterprise/report-cloud-pc-recommendations.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -42,11 +42,9 @@ An evolving model analyzes this data to determine whether Cloud PCs are:
4242
- Under-used.
4343
- Sized appropriately.
4444

45-
The Cloud PC recommendations report is in [public preview](..\public-preview.md).
46-
4745
## Use the Cloud PC recommendations report
4846

49-
To get to the **Cloud PC recommendations** report, sign in to [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Reports** > **Cloud PC Overview** > **Cloud PC recommendations (preview)**.
47+
To get to the **Cloud PC recommendations** report, sign in to [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Reports** > **Cloud PC Overview** > **Cloud PC recommendations**.
5048

5149
![Screenshot of Cloud PC recommendation report.](media/report-cloud-pc-recommendations/report-cloud-pc-recommendations.png)
5250

0 commit comments

Comments
 (0)