mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 05:17:22 +00:00
3.4 KiB
3.4 KiB
title, description, ms.topic, ms.date
title | description | ms.topic | ms.date |
---|---|---|---|
Disable hibernation for PDE in Intune | Disable hibernation for PDE in Intune | how-to | 03/13/2023 |
Disable hibernation for PDE
Hibernation files can potentially cause the keys used by Personal Data Encryption (PDE) to protect content to be exposed. For greatest security, disable hibernation.
Disable hibernation in Intune
To disable hibernation using Intune, follow the below steps:
- Sign in to the Microsoft Intune admin center
- In the Home screen, select Devices in the left pane
- In the Devices | Overview screen, under Policy, select Configuration Profiles
- In the Devices | Configuration profiles screen, make sure Profiles is selected at the top, and then select Create profile
- In the Create profile window that opens:
- Under Platform, select Windows 10 and later
- Under Profile type, select Settings catalog
- Select Create to close the Create profile window
- The Create profile screen will open. In the Basics page:
- Next to Name, enter Disable Hibernation
- Next to Description, enter a description
- Select Next
- In the Configuration settings page:
- select Add settings
- In the Settings picker window that opens:
- Under Browse by category, scroll down and select Power
- When the settings for the Power category appear under Setting name in the lower pane, select Allow Hibernate, and then select the X in the top right corner of the Settings picker window to close the window
- Change Allow Hibernate from Allow to Block by selecting the slider next to the option
- Select Next
- In the Scope tags page, configure if necessary and then select Next
- In the Assignments page:
- Under Included groups, select Add groups
Note
Make sure to add the correct groups under Included groups and not under Excluded groups. Accidentally adding the desired device groups under Excluded groups will result in those devices being excluded and they won't receive the configuration profile.
- In the Select groups to include window that opens, select the groups that the configuration profile should be assigned to, and then select Select to close the Select groups to include window
- Under Included groups > Groups, ensure the correct group(s) are selected, and then select Next
- Under Included groups, select Add groups
- In Review + create page, review the configuration to make sure everything is configured correctly, and then select Create
Additional PDE configurations in Intune
The following PDE configurations can also be configured using Intune:
Prerequisites
Security hardening recommendations
- Disable kernel-mode crash dumps and live dumps
- Disable Windows Error Reporting (WER)/user-mode crash dumps
- Disable allowing users to select when a password is required when resuming from connected standby