Microsoft Intune admin center | Security Incident Triage
🚨 SEV-2 SOC ALERT #INC-8092
tenant: contoso-rcw.onmicrosoft.com | 👤 Pradeep Raju (SecAdmin)

Security Incident Overview — SOC Alert #INC-8092

🚨 ACTIVE SECURITY ALERT: 65% of Executive & Finance Fleet is Non-Compliant!

Corporate laptops are missing BitLocker full-disk encryption and have disabled Defender real-time protection, violating CIS Microsoft Intune Benchmark v3.0.

Fleet Compliance Health
35%
Critical Risk: Target is 100%
Unencrypted BitLocker Disks
5
Executive & Finance Laptops
Defender Real-time Disabled
2
Tamper Protection Inactive

🎯 Your 5 Challenge Missions:

  1. Mission 1: Configure and deploy a Silent BitLocker 256-bit AES-XTS Encryption Policy with TPM key escrow to Entra ID.
  2. Mission 2: Enforce Microsoft Defender Real-Time & Tamper Protection endpoint security baselines.
  3. Mission 3: Configure Zero-Trust Conditional Access to block non-compliant devices from Microsoft 365 Exchange & Teams.
  4. Mission 4: Run Intune Proactive Remediations to auto-remediate unencrypted drives across the fleet.
  5. Mission 5: Re-evaluate compliance and restore 100% Fleet Zero-Trust Health to close the SOC incident.