In #Intune BitLocker & Defender can be set via Configuration Profile, Security Baseline & Endpoint Security; Password complexity in Compliance Policies & Device Restrictions.
Why in multiple places?
Does it matter?
What's the benefit?
What's the drawback?
What's leading practice?
We've been digging into why some ASR rules weren't getting applied. Documentation states ASR rules merge but that's not happening. learn.microsoft.com/en-us/mem/intu…
In peeling this progressively stinky onion we learned that the configuration overlap isn't unique to ASR's but multiple settings making it really easy to create conflicts, discrepanciesor unexpected results.
What are the pros & cons for figuring things in one area over another?
Very interested in hearing from anyone who has done that sort of deep dive analysis on where to configure things in #MSIntune. Seems like a some policy reconfigurations may be needed but I can't proceed in good conscience without guidance @IntuneSuppTeam@IntuneTraining@intune
• • •
Missing some Tweet in this thread? You can try to
force a refresh