Problem Statement
How would you roll out full-disk encryption at scale and avoid data-loss surprises?
Explanation
Pick native tooling (BitLocker on Windows, LUKS on Linux) and integrate with key escrow so recovery keys are backed up securely. Pilot on a small group, validate performance and recovery flows, then phase to wider groups. Enforce pre-boot authentication where risk warrants and verify that recovery keys are retrievable before enabling at scale. Document support steps, train service desk, and test lost-device and rebuild scenarios. This balances confidentiality with operational safety and prevents lock-out incidents.
Code Solution
SolutionRead Only
Windows: enable BitLocker with escrow to Azure AD/MBAM Linux: cryptsetup luksFormat + enroll keys; store recovery in vault
