encryption
61 TopicsBitLocker recovery key not being uploaded into Intune when using BackupToAAD-BitLockerKeyProtector
Hello, We are having an issue with the BackupToAAD-BitLockerKeyProtector PowerShell cmdlet to upload the BitLocker recovery key of our devices into AAD/Intune. We currently use Sophos Device Encryption to encrypt our devices but want to migrate the recovery keys into Intune as we transition to Intune BitLocker policies. We created a script that attempts to upload the BitLocker recovery key into Intune but it appears the BackupToAAD-BitLockerKeyProtector cmdlet only works on devices where the user logs in with a domain account, and not a local Windows account. Is this standard behaviour? I would have assumed that since the device is enrolled into Intune it would use the Management Extension to communicate with Intune for this task - and have no reliance on the logged in user. Looking at the BitLocker PowerShell module itself, a method named " BackupRecoveryInformationToCloudDomain" is called when this cmdlet is executed. I haven't been able to find much online about what happens beyond here. It would be good to know a bit more about this cmdlet as documentation is limited online. CheersSolved38KViews0likes7CommentsEncrypting and Decrypting sensitive Information in ASP.NET Core
In today’s digital landscape, securing sensitive information is more critical than ever. If you're using ASP.NET Core, you might store configuration settings in appsettings.json. However, hardcoding sensitive data like connection strings or API keys in plain text can expose your application to serious risks.11KViews1like0CommentsEncrypting a SharePoint List
Hi We are developing a solution that will save sensitive info on a SharePoint List. Thinking to use Sensitivity labels to encrypt the info. It is possible to: Encrypt certain columns? if not Certain List Certain site... Where can I find some instructions on how to achieve this? I assume a form in MS forms is not encrypted? ThanksSolved8KViews0likes3CommentsOutlook message encryption - avoid delegate access
Dear community, we have following challenge. We would like to use the message encryption option (OME) It´s simple to implement and fits for most of our needs. However we have one scenario where it doesnt fits or at least I couldnt find a solution in this community or in Internet. Our director wants to delegate access to his assistant including inbox but shouldnt be able read encrypted emails Is there a solution for this? Thanks for your support...7.2KViews1like11CommentsRAID Array / Disk Performance with Bitlocker - unexpected results
I've doing some testing on a system to identify the impact that Bitlocker Encryption has on the read/write performance and the results have been interesting to say the least; I'm hoping someone can help to explain my findings. I'm using an entry level server with quad core Xeon E-2224 CPU and 16GB RAM which has Windows Sever 2016 Standard installed - and it's a totally fresh Windows install with all of the latest relevant drivers are installed. My storage array is configured through the integrated controller on the motherboard and is across 4 x 10TB WD Enterprise disks configured as follows: RAID Level RAID5 Legacy Disk Geometry (C/H/S) 65535/255/32 Strip Size 64 KiB Full Stripe Size 192 KiB Disk 0 WDC WD102KRYZ-0 Disk 1 WDC WD102KRYZ-0 Disk 2 WDC WD102KRYZ-0 Disk 3 WDC WD102KRYZ-0 I've provisioned a single large logical volume and I've created two partitions for my testing as follows: Drive Capacity File System Allocation Unit Size Y: 100 GB NTFS 4096 bytes Z: 25,600 GB NTFS 8192 bytes I ran an array of tests (results attached) on the volumes before encryption, then reformatted and encrypted the volumes and same tests again. The results have been very interesting, I was expecting to see a small performance hit across all tests due to Bitlocker, but what I found was that some tests had a drastic performance decrease, in some cases up to 50%, and surprisingly some tests showed an increase in performance, in one case an increase of 60%. Can anyone help to explain this? I'm thinking of running the tests again with another product to see if I get similar results, but what I'm using is fairly robust/reliable from my experience. Findings are in the spreadsheet attached.6.6KViews1like0CommentsWhere and how are the Outlook Message Encryption templates managed?
We have Microsoft 365 Business Premium licenses. Within Outlook, when you create a new email and go to the Options tab, there is an Encrypt button with the following options; Encrypt-Only, Do Not Forward, Confidential - All Employees, and Highly Confidential - All Employees. I want to see if I can create some specific ones for certain use cases but I'll be damned if I can find where these are set. I would also like to find out the specific restrictions each of these puts in place. I can distinctly remember messing around with message encryption templates a year (or more) ago but fast forward to today and everything seems to be retired or replaced or moved and I can't for the life of me locate where these email encryption templates are located. The MS docs are all over the place and searching for things in the Azure portal pull up nothing (or old docs that aren't current anymore). I know labels are now a big thing and maybe I missed migrating these encryption templates to labels? (in my searches I've seen ARM then Azure Information Protection which seems to be replaced by Rights Management Service and then talk about labels...)5.3KViews0likes2Comments