Implementing Disk Encryption with BitLocker When to Use Use this skill when: - Encrypting Windows endpoints to protect data at rest for compliance (PCI DSS, HIPAA, GDPR) - Deploying BitLocker across enterprise fleet via Intune, SCCM, or GPO - Configuring TPM-based encryption with PIN or USB startup key for enhanced security - Managing BitLocker recovery keys in Active Directory or Azure AD Do not use this skill for Linux disk encryption (use LUKS/dm-crypt) or macOS (use FileVault). Prerequisites - Windows 10/11 Pro, Enterprise, or Education edition - TPM 2.0 chip (recommended; TPM 1.2 support…