Courseiva

MD-102 Manage and maintain devices Practice Question

A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?

⚠ Common exam trap

Candidates often assume enabling FileVault alone satisfies compliance, but Intune requires the recovery key to be escrowed to confirm full manageability and recovery capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The recovery key is not escrowed to Intune.

The most likely cause is that the recovery key is not escrowed to Intune. Even though FileVault is enabled on the device, Intune's compliance policy checks for the presence of the FileVault recovery key in its escrow database. If the key is missing, the device is marked non-compliant because Intune cannot verify full management and recovery capability, which is a key security requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FileVault is not actually enabled on those devices.

    Why it's wrong here

    FileVault being disabled would produce this non-compliance, but the audit already confirmed encryption is enabled on those devices, so this contradicts the evidence. It is tempting because disabled encryption is the obvious cause of a FileVault compliance failure, and would be correct if the devices genuinely lacked encryption.

  • ✓

    The recovery key is not escrowed to Intune.

    Why this is correct

    FileVault being enabled is insufficient for compliance because Intune requires the personal recovery key to be escrowed before it reports the device as compliant. Without escrow, Intune cannot verify key custody, so the device shows non-compliant despite active encryption.

  • ✗

    The devices are not supervised.

    Why it's wrong here

    FileVault status is reported through the personal recovery key escrow, which requires supervision; unsupervised Macs can have FileVault on yet still report non-compliant. Supervision is genuinely needed for automated device enrolment and configuration profiles, but the stem already shows encryption enabled, so it is not the cause here.

  • ✗

    The compliance policy is not assigned to those devices.

    Why it's wrong here

    Devices without the policy assigned would not appear in its compliance report at all, so they cannot be the 10% shown as non-compliant. Assignment scoping is the right fix when devices are missing from reporting entirely, not when they report a failing state despite meeting the requirement.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MD-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses Microsoft Intune to manage macOS devices. They need to enforce FileVault encryption on all Macs. What should they configure?

easy
  • A.An endpoint security policy for disk encryption.
  • ✓ B.A device configuration profile with FileVault settings.
  • C.A device compliance policy that requires FileVault.
  • D.An app protection policy.

Why B: FileVault encryption on macOS is enforced through a device configuration profile in Microsoft Intune. Specifically, you create a settings catalog or a custom profile that includes the FileVault settings under the 'System Preferences' > 'Security & Privacy' category, which allows you to require FileVault and escrow the recovery key to Intune. This is the native Intune method for managing macOS disk encryption, as endpoint security policies for disk encryption are designed for Windows BitLocker, not macOS.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.