mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-05 17:17:22 +00:00
5.7 KiB
5.7 KiB
title, description, author, ms.author, ms.reviewer, manager, ms.topic, ms.prod, ms.technology, ms.localizationpriority, ms.date
title | description | author | ms.author | ms.reviewer | manager | ms.topic | ms.prod | ms.technology | ms.localizationpriority | ms.date |
---|---|---|---|---|---|---|---|---|---|---|
Configure Personal Data Encryption (PDE) in Intune | Configuring and enabling Personal Data Encryption (PDE) required and recommended policies in Intune | frankroj | frankroj | rafals | aaroncz | how-to | windows-client | itpro-security | medium | 09/22/2022 |
Configure Personal Data Encryption (PDE) policies in Intune
Required prerequisites
Enable Personal Data Encryption (PDE)
- Sign into the Intune
- Navigate to Devices > Configuration Profiles
- Select Create profile
- Under Platform, select Windows 10 and later
- Under Profile type, select Templates
- Under Template name, select Custom, and then select Create
- On the **Basics tab:
- Next to Name, enter Personal Data Encryption
- Next to Description, enter a description
- Select Next
- On the Configuration settings tab, select Add
- In the Add Row window:
- Next to Name, enter Personal Data Encryption
- Next to Description, enter a description
- Next to OMA-URI, enter in ./User/Vendor/MSFT/PDE/EnablePersonalDataEncryption
- Next to Data type, select Integer
- Next to Value, enter in 1
- Select Save, and then select Next
- On the Assignments tab:
- Under Included groups, select Add groups
- Select the groups that the PDE policy should be deployed to
- Select Select
- Select Next
- On the Applicability Rules tab, configure if necessary and then select Next
- On the Review + create tab, review the configuration to make sure everything is configured correctly, and then select Create
Disable Winlogon automatic restart sign-on (ARSO)
- Sign into the Intune
- Navigate to Devices > Configuration Profiles
- Select Create profile
- Under Platform, select Windows 10 and later
- Under Profile type, select Templates
- Under Template name, select Administrative templates, and then select Create
- On the **Basics tab:
- Next to Name, enter Disable ARSO
- Next to Description, enter a description
- Select Next
- On the Configuration settings tab, under Computer Configuration, navigate to Windows Components > Windows Logon Options
- Select Sign-in and lock last interactive user automatically after a restart
- In the Sign-in and lock last interactive user automatically after a restart window that opens, select Disabled, and then select OK
- Select Next
- On the Scope tags tab, configure if necessary and then select Next
- On the Assignments tab:
- Under Included groups, select Add groups
- Select the groups that the ARSO policy should be deployed to
- Select Select
- Select Next
- On the Review + create tab, review the configuration to make sure everything is configured correctly, and then select Create
Recommended prerequisites
Disable crash dumps
- Sign into the Intune
- Navigate to Devices > Configuration Profiles
- Select Create profile
- Under Platform, select Windows 10 and later
- Under Profile type, select Settings catalog, and then select Create
- On the **Basics tab:
- Next to Name, enter Disable Hibernation
- Next to Description, enter a description
- Select Next
- On the Configuration settings tab, select Add settings
- In the Settings picker windows, select Memory Dump
- When the settings appear in the lower pane, under Setting name, select both Allow Crash Dump and Allow Live Dump, and then select the X in the top right corner of the Settings picker window to close the window
- Change both Allow Live Dump and Allow Crash Dump to Block, and then select Next
- On the Scope tags tab, configure if necessary and then select Next
- On the Assignments tab:
- Under Included groups, select Add groups
- Select the groups that the crash dumps policy should be deployed to
- Select Select
- Select Next
- On the Review + create tab, review the configuration to make sure everything is configured correctly, and then select Create
Disable hibernation
- Sign into the Intune
- Navigate to Devices > Configuration Profiles
- Select Create profile
- Under Platform, select Windows 10 and later
- Under Profile type, select Settings catalog, and then select Create
- On the **Basics tab:
- Next to Name, enter Disable Hibernation
- Next to Description, enter a description
- Select Next
- On the Configuration settings tab, select Add settings
- In the Settings picker windows, select Power
- When the settings appear in the lower pane, under Setting name, select Allow Hibernate, and then select the X in the top right corner of the Settings picker window to close the window
- Change Allow Hibernate to Block, and then select Next
- On the Scope tags tab, configure if necessary and then select Next
- On the Assignments tab:
- Under Included groups, select Add groups
- Select the groups that the hibernation policy should be deployed to
- Select Select
- Select Next
- On the Review + create tab, review the configuration to make sure everything is configured correctly, and then select Create