9.2 KiB
title, description, author, ms.author, ms.reviewer, manager, ms.topic, ms.prod, ms.technology, ms.localizationpriority, ms.date
title | description | author | ms.author | ms.reviewer | manager | ms.topic | ms.prod | ms.technology | ms.localizationpriority | ms.date |
---|---|---|---|---|---|---|---|---|---|---|
Configure Personal Data Encryption (PDE) in Intune | Configuring and enabling Personal Data Encryption (PDE) required and recommended policies in Intune | frankroj | frankroj | rhonnegowda | aaroncz | how-to | windows-client | itpro-security | medium | 12/13/2022 |
Configure Personal Data Encryption (PDE) policies in Intune
Required prerequisites
Enable Personal Data Encryption (PDE)
-
Sign into Intune admin center.
-
Navigate to Devices > Configuration Profiles
-
Select Create profile
-
Under Platform, select Windows 10 and later
-
Under Profile type, select Templates
-
Under Template name, select Custom, and then select Create
-
In Basics:
- Next to Name, enter Personal Data Encryption
- Next to Description, enter a description
-
Select Next
-
In Configuration settings, select Add
-
In Add Row:
- Next to Name, enter Personal Data Encryption
- Next to Description, enter a description
- Next to OMA-URI, enter in ./User/Vendor/MSFT/PDE/EnablePersonalDataEncryption
- Next to Data type, select Integer
- Next to Value, enter in 1
-
Select Save, and then select Next
-
In Assignments:
- Under Included groups, select Add groups
- Select the groups that the PDE policy should be deployed to
- Select Select
- Select Next
-
In Applicability Rules, configure if necessary and then select Next
-
In Review + create, review the configuration to make sure everything is configured correctly, and then select Create
Disable Winlogon automatic restart sign-on (ARSO)
-
Sign into Intune admin center.
-
Navigate to Devices > Configuration Profiles
-
Select Create profile
-
Under Platform, select Windows 10 and later
-
Under Profile type, select Templates
-
Under Template name, select Administrative templates, and then select Create
-
In Basics:
- Next to Name, enter Disable ARSO
- Next to Description, enter a description
-
Select Next
-
In Configuration settings, under Computer Configuration, navigate to Windows Components > Windows Logon Options
-
Select Sign-in and lock last interactive user automatically after a restart
-
In the Sign-in and lock last interactive user automatically after a restart window that opens, select Disabled, and then select OK
-
Select Next
-
In Scope tags, configure if necessary and then select Next
-
In Assignments:
- Under Included groups, select Add groups
- Select the groups that the ARSO policy should be deployed to
- Select Select
- Select Next
-
In Review + create, review the configuration to make sure everything is configured correctly, and then select Create
Security hardening recommendations
Disable kernel-mode crash dumps and live dumps
-
Sign into Intune admin center.
-
Navigate to Devices > Configuration Profiles
-
Select Create profile
-
Under Platform, select Windows 10 and later
-
Under Profile type, select Settings catalog, and then select Create
-
In Basics:
- Next to Name, enter Disable Kernel-Mode Crash Dumps
- Next to Description, enter a description
-
Select Next
-
In Configuration settings, select Add settings
-
In the Settings picker window, under Browse by category, select Memory Dump
-
When the settings appear under Setting name, select both Allow Crash Dump and Allow Live Dump, and then select the X in the top right corner of the Settings picker window to close the window
-
Change both Allow Live Dump and Allow Crash Dump to Block, and then select Next
-
In Scope tags, configure if necessary and then select Next
-
In Assignments:
- Under Included groups, select Add groups
- Select the groups that the disable crash dumps policy should be deployed to
- Select Select
- Select Next
-
In Review + create, review the configuration to make sure everything is configured correctly, and then select Create
Disable Windows Error Reporting (WER)/Disable user-mode crash dumps
-
Sign into Intune admin center.
-
Navigate to Devices > Configuration Profiles
-
Select Create profile
-
Under Platform, select Windows 10 and later
-
Under Profile type, select Settings catalog, and then select Create
-
In Basics:
- Next to Name, enter Disable Windows Error Reporting (WER)
- Next to Description, enter a description
-
Select Next
-
In Configuration settings, select Add settings
-
In the Settings picker window, under Browse by category, expand to Administrative Templates > Windows Components, and then select Windows Error Reporting
-
When the settings appear under Setting name, select Disable Windows Error Reporting, and then select the X in the top right corner of the Settings picker window to close the window
-
Change Disable Windows Error Reporting to Enabled, and then select Next
-
In Scope tags, configure if necessary and then select Next
-
In Assignments:
- Under Included groups, select Add groups
- Select the groups that the disable WER dumps policy should be deployed to
- Select Select
- Select Next
-
In Review + create, review the configuration to make sure everything is configured correctly, and then select Create
Disable hibernation
-
Sign into Intune admin center.
-
Navigate to Devices > Configuration Profiles
-
Select Create profile
-
Under Platform, select Windows 10 and later
-
Under Profile type, select Settings catalog, and then select Create
-
In Basics:
- Next to Name, enter Disable Hibernation
- Next to Description, enter a description
-
Select Next
-
In Configuration settings, select Add settings
-
In the Settings picker window, under Browse by category, select Power
-
When the settings appear under Setting name, select Allow Hibernate, and then select the X in the top right corner of the Settings picker window to close the window
-
Change Allow Hibernate to Block, and then select Next
-
In Scope tags, configure if necessary and then select Next
-
In Assignments:
- Under Included groups, select Add groups
- Select the groups that the disable hibernation policy should be deployed to
- Select Select
- Select Next
-
In Review + create, review the configuration to make sure everything is configured correctly, and then select Create
Disable allowing users to select when a password is required when resuming from connected standby
-
Sign into Intune admin center.
-
Navigate to Devices > Configuration Profiles
-
Select Create profile
-
Under Platform, select Windows 10 and later
-
Under Profile type, select Settings catalog, and then select Create
-
In Basics:
- Next to Name, enter Disable allowing users to select when a password is required when resuming from connected standby
- Next to Description, enter a description
-
Select Next
-
In Configuration settings, select Add settings
-
In the Settings picker window, under Browse by category, expand to Administrative Templates > System, and then select Logon
-
When the settings appear under Setting name, select Allow users to select when a password is required when resuming from connected standby, and then select the X in the top right corner of the Settings picker window to close the window
-
Make sure that Allow users to select when a password is required when resuming from connected standby is left at the default of Disabled, and then select Next
-
In Scope tags, configure if necessary and then select Next
-
In Assignments:
- Under Included groups, select Add groups
- Select the groups that the disable Allow users to select when a password is required when resuming from connected standby policy should be deployed to
- Select Select
- Select Next
-
In Review + create, review the configuration to make sure everything is configured correctly, and then select Create