A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?
The endpoint security disk encryption policy is the built-in Intune workload for FileVault, applying the required encryption settings to macOS devices without a custom profile. This satisfies the scenario's need to enforce FileVault through a supported policy type.
Why this answer
Intune provides a built-in endpoint security disk encryption policy for macOS that enforces FileVault encryption. This is the recommended approach because it integrates natively with Intune, allows assignment to device groups, and reports compliance status without requiring third-party tools or manual user action.
Exam trap
MD-102 often tests the preference for native Intune policies over third-party tools or manual methods — candidates may overcomplicate by choosing Apple Configurator or JAMF Pro when Intune has a built-in solution.
How to eliminate wrong answers
Option B is wrong because while Apple Configurator can create custom profiles, importing them into Intune is not the recommended approach for FileVault when a native Intune policy exists; it adds unnecessary complexity. Option C is wrong because asking users to manually enable FileVault is not a managed, enforceable solution and defeats the purpose of MDM. Option D is wrong because JAMF Pro is a third-party tool; while it can manage FileVault, the question specifies Intune as the management tool, so using JAMF Pro is out of scope.