You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/protect/encrypt-devices-filevault.md
+62-61Lines changed: 62 additions & 61 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,18 +1,18 @@
1
1
---
2
2
# required metadata
3
-
title: Encrypt macOS devices with FileVault disk encryption with Intune
3
+
title: Encrypt macOS FileVault disk encryption with Intune policy
4
4
titleSuffix: Microsoft Intune
5
-
description: Use Microsoft Intune encryption policy to encrypt macOS devices with FileVault, and manage recovery keys for encrypted macOS devices from within the Microsoft Intune admin center.
5
+
description: Use Microsoft Intune policy to configure FileVault on macOS devices, and use the admin center to manage their recovery keys.
6
6
keywords:
7
7
author: brenduns
8
8
ms.author: brenduns
9
9
manager: dougeby
10
-
ms.date: 06/21/2024
10
+
ms.date: 10/25/2024
11
11
ms.topic: how-to
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
14
14
ms.localizationpriority: high
15
-
ms.assetid:
15
+
ms.assetid:
16
16
17
17
# optional metadata
18
18
@@ -30,7 +30,7 @@ ms.collection:
30
30
31
31
---
32
32
33
-
# Use FileVault disk encryption for macOS with Intune
33
+
# Use FileVault disk encryption for macOS with Intune
34
34
35
35
Use Microsoft Intune to configure and manage macOS FileVault disk encryption. FileVault is a whole-disk encryption program that is included with macOS. With Intune you can deploy policies that configure FileVault, and then manage recovery keys on devices that run **macOS 10.13 or later**.
36
36
@@ -66,62 +66,18 @@ You can add this permission and right to your own [custom RBAC roles](../fundame
66
66
- Help Desk Operator
67
67
- Endpoint Security Administrator
68
68
69
-
## Create device configuration policy for FileVault
70
-
71
-
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
72
-
73
-
2. Select **Devices** > **Manage devices** > **Configuration** > On the *Policies* tab, select **+ Create**.
74
-
75
-
3. On the **Create a profile** page, set the following options, and then select **Create**:
76
-
-**Platform**: macOS
77
-
-**Profile type**: Templates
78
-
-**Template name**: Endpoint protection
79
-
80
-
:::image type="content" source="./media/encrypt-devices-filevault/select-macos-filevault-dc.png" alt-text="Select the Endpoint protection profile.":::
81
-
82
-
4. On the **Basics** page, enter the following properties:
83
-
84
-
-**Name**: Enter a descriptive name for the policy. Name your policies so you can easily identify them later. For example, a good policy name might include the profile type and platform.
85
-
86
-
-**Description**: Enter a description for the policy. This setting is optional, but recommended.
87
-
88
-
5. On the **Configuration settings** page, select **FileVault** to expand the available settings:
- For *Recovery key type*, select **Personal key**.
97
-
98
-
- For *Escrow location description of personal recovery key*, add a message to help guide users on [how to retrieve the recovery key](#retrieve-a-personal-recovery-key) for their device. This information can be useful for your users when you use the setting for Personal recovery key rotation, which can automatically generate a new recovery key for a device periodically.
99
-
100
-
For example: To retrieve a lost or recently rotated recovery key, sign in to the Intune Company Portal website from any device. In the portal, go to *Devices* and select the device that has FileVault enabled, and then select *Get recovery key*. The current recovery key is displayed.
101
-
102
-
Configure the remaining [FileVault settings](endpoint-protection-macos.md#filevault) to meet your business needs, and then select **Next**.
103
-
104
-
7. If applicable, on the **Scope (Tags)** page, choose **Select scope tags** to open the Select tags pane to assign scope tags to the profile.
105
-
106
-
Select **Next** to continue.
107
-
108
-
8. On the **Assignments** page, select groups to receive this profile. For more information on assigning profiles, see Assign user and device profiles.
109
-
Select **Next**.
110
-
111
-
9. On the **Review + create** page, when you're done, choose **Create**. The new profile is displayed in the list when you select the policy type for the profile you created.
112
-
113
69
## Create endpoint security policy for FileVault
114
70
115
71
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
1. On the **Basics** page, enter the following properties, and then choose **Next**.
120
-
-**Platform**: macOS
121
-
-**Profile**: FileVault
75
+
3. On the **Basics** page, enter the following properties, and then choose **Next**.
76
+
-**Platform**: macOS
77
+
-**Profile**: FileVault
122
78
123
79

124
-
80
+
125
81
4. On the **Configuration settings** page:
126
82
1. Set *Enable FileVault* to **Yes**.
127
83
2. For *Recovery key type*, only **Personal Recovery Key** is supported.
@@ -172,7 +128,7 @@ Select **Next**.
172
128
173
129
7. If applicable, on the **Scope (Tags)** page, choose **Select scope tags** to open the *Select tags* pane to assign scope tags to the profile. Select **Next** to continue.
174
130
175
-
8. On the **Assignments** page, select the groups that will receive this profile. For more information on assigning profiles, see Assign user and device profiles. Select **Next**.
131
+
8. On the **Assignments** page, select the groups that receive this profile. For more information on assigning profiles, see Assign user and device profiles. Select **Next**.
176
132
177
133
9. On the **Review + create** page, when you're done, select **Create**. The new profile is displayed in the list when you select the policy type for the profile you created.
178
134
@@ -187,16 +143,61 @@ For devices that run macOS 14 and later, your settings catalog policy can also e
187
143
- When *Await final Configuration* set to *Yes* for a device, you can then add the following Full Disk Encryption setting for FileVault in your settings catalog profile
188
144
189
145
- FileVault > **Force Enable in Setup Assistant** – Set to **Enabled**.
190
-
146
+
191
147
The following image shows the settings catalog profile configured with the core settings to enable FileVault and use the Setup Assistant to enforce encryption. In this example, the Location setting uses the simple name of our domain, *Contoso*:
192
148
193
-
194
-
195
149
> [!IMPORTANT]
196
150
> The **Defer** setting must be configured to **Enabled** to successfully enable FileVault in Setup Assistant for devices running macOS 14.4.
197
-
151
+
198
152
:::image type="content" source="./media/encrypt-devices-filevault/filevault-setup-assistant-configuration.png" alt-text="Screenshot of the settings needed to enable File Vault in Setup Assistant.":::
199
153
154
+
## Create device configuration policy for FileVault (Deprecated)
155
+
156
+
> [!NOTE]
157
+
> The macOS template for Endpoint Protection is deprecated and no longer supports creating new profiles. Instead, use the [Endpoint security](#create-endpoint-security-policy-for-filevault) or the [settings catalog](#create-settings-catalog-policy-for-filevault) to configure and manage new FileVault profiles.
158
+
159
+
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
160
+
161
+
2. Select **Devices** > **Manage devices** > **Configuration** > On the *Policies* tab, select **+ Create**.
162
+
163
+
3. On the **Create a profile** page, set the following options, and then select **Create** > **New policy**:
:::image type="content" source="./media/encrypt-devices-filevault/select-macos-filevault-dc.png" alt-text="Screen shot that displays the the Endpoint protection profile.":::
169
+
170
+
4. On the **Basics** page, enter the following properties:
171
+
172
+
-**Name**: Enter a descriptive name for the policy. Name your policies so you can easily identify them later. For example, a good policy name might include the profile type and platform.
173
+
174
+
-**Description**: Enter a description for the policy. This setting is optional, but recommended.
175
+
176
+
5. On the **Configuration settings** page, select **FileVault** to expand the available settings:
177
+
178
+
:::image type="content" source="./media/encrypt-devices-filevault/filevault-settings.png" alt-text="Screen shot that displays FileVault settings.":::
179
+
180
+
6. Configure the following settings:
181
+
182
+
- For *Enable FileVault*, select **Yes**.
183
+
184
+
- For *Recovery key type*, select **Personal key**.
185
+
186
+
- For *Escrow location description of personal recovery key*, add a message to help guide users on [how to retrieve the recovery key](#retrieve-a-personal-recovery-key) for their device. This information can be useful for your users when you use the setting for Personal recovery key rotation, which can automatically generate a new recovery key for a device periodically.
187
+
188
+
For example: To retrieve a lost or recently rotated recovery key, sign in to the Intune Company Portal website from any device. In the portal, go to *Devices* and select the device that has FileVault enabled, and then select *Get recovery key*. The current recovery key is displayed.
189
+
190
+
Configure the remaining [FileVault settings](endpoint-protection-macos.md#filevault) to meet your business needs, and then select **Next**.
191
+
192
+
7. If applicable, on the **Scope (Tags)** page, choose **Select scope tags** to open the Select tags pane to assign scope tags to the profile.
193
+
194
+
Select **Next** to continue.
195
+
196
+
8. On the **Assignments** page, select groups to receive this profile. For more information on assigning profiles, see Assign user and device profiles.
197
+
Select **Next**.
198
+
199
+
9. On the **Review + create** page, when you're done, choose **Create**. The new profile is displayed in the list when you select the policy type for the profile you created.
200
+
200
201
## Manage FileVault
201
202
202
203
To view information about devices that receive FileVault policy, see [Monitor disk encryption](../protect/encryption-monitor.md).
@@ -224,7 +225,7 @@ Intune can’t manage FileVault disk encryption on a macOS device that is encryp
224
225
-[Upload a personal recovery key to Intune](#upload-a-personal-recovery-key) – Use this method when the user knows their personal recovery key.
225
226
-[The user generates a new recovery key on the device](#generate-a-new-recovery-key-on-the-device) – Use this method if the personal recovery key isn’t known by the user.
226
227
227
-
Both methods require that the device has active policy from Intune that manages FileVault encryption. To deliver this policy, you can use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), or a [device configuration endpoint protection profile](#create-device-configuration-policy-for-filevault) to encrypt devices with FileVault.
228
+
Both methods require that the device has active policy from Intune that manages FileVault encryption. To deliver this policy, use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault).
228
229
229
230
#### Upload a personal recovery key
230
231
@@ -238,7 +239,7 @@ Upon upload, Intune rotates the key to create a new personal recovery key. Intun
238
239
239
240
Before Intune can assume management of encryption of a user-encrypted device, that device must receive an Intune FileVault policy for disk encryption.
240
241
241
-
Use either an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), or a [device configuration endpoint protection profile](#create-device-configuration-policy-for-filevault) to encrypt devices with FileVault.
242
+
Use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), to encrypt devices with FileVault.
242
243
243
244
-**The user who encrypted the device must have access to their personal recovery key for the device and be directed to upload it to Intune.**
244
245
@@ -271,7 +272,7 @@ To enable Intune to manage FileVault on a previously encrypted device, the user
271
272
272
273
Before Intune can assume management of encryption of a user-encrypted device, that device must receive an Intune FileVault policy for disk encryption.
273
274
274
-
Use either an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault), or a [device configuration endpoint protection profile](#create-device-configuration-policy-for-filevault) to encrypt devices with FileVault.
275
+
Use an [endpoint security disk encryption profile](#create-endpoint-security-policy-for-filevault) to encrypt devices with FileVault.
275
276
276
277
-**The device user must have access to the Terminal app on the encrypted device.**
Copy file name to clipboardExpand all lines: memdocs/intune/protect/endpoint-protection-macos.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: lenewsad
8
8
ms.author: lanewsad
9
9
manager: dougeby
10
-
ms.date: 08/15/2022
10
+
ms.date: 10/25/2024
11
11
ms.topic: reference
12
12
ms.service: microsoft-intune
13
13
ms.subservice: protect
@@ -32,7 +32,9 @@ ms.collection:
32
32
# macOS endpoint protection settings in Intune
33
33
34
34
> [!IMPORTANT]
35
-
> The macOS endpoint protection template has been deprecated. Existing policies remain unchanged, but you can no longer create new policies using this template. We recommend using the settings catalog to create new configuration policies for FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. For more information, see [macOS settings catalog](../configuration/settings-catalog.md).
35
+
> The macOS endpoint protection template has been deprecated. Existing policies remain unchanged, but you can no longer create new policies using this template. > Instead, use one of the following options:
36
+
> - Use Endpoint security policies like [disk encryption](../protect/endpoint-security-disk-encryption-policy.md) for Filevault, or [Firewall](../protect/endpoint-security-firewall-policy.md) policy.
37
+
> - Use the Settings catalog to create new configuration policies for FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. For more information, see [macOS settings catalog](../configuration/settings-catalog.md).
36
38
37
39
This article shows you the endpoint protection settings that you can configure for devices that run macOS. You configure these settings by using a macOS device configuration profile for [endpoint protection](endpoint-protection-configure.md) in Intune.
Copy file name to clipboardExpand all lines: windows-365/enterprise/report-cloud-pc-recommendations.md
+1-3Lines changed: 1 addition & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -42,11 +42,9 @@ An evolving model analyzes this data to determine whether Cloud PCs are:
42
42
- Under-used.
43
43
- Sized appropriately.
44
44
45
-
The Cloud PC recommendations report is in [public preview](..\public-preview.md).
46
-
47
45
## Use the Cloud PC recommendations report
48
46
49
-
To get to the **Cloud PC recommendations** report, sign in to [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Reports** > **Cloud PC Overview** > **Cloud PC recommendations (preview)**.
47
+
To get to the **Cloud PC recommendations** report, sign in to [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Reports** > **Cloud PC Overview** > **Cloud PC recommendations**.
50
48
51
49

0 commit comments