Courseiva
Manage and maintain devices →mediumMultiple Choice

Configuring BitLocker Encryption Policy in Microsoft Intune

Your organization uses Microsoft Intune to manage Windows 11 devices. You have a requirement to ensure that all devices have BitLocker Drive Encryption enabled with a TPM protector and a recovery key escrowed to Microsoft Entra ID. Additionally, you need to configure a policy that prevents users from changing the BitLocker settings. You create a device configuration profile using the 'Endpoint Protection' template for Windows 10 and later. After deploying the policy to a test group, you notice that BitLocker is not enabled on some devices. The devices meet the hardware requirements and are Microsoft Entra ID joined. What is the most likely reason for the failure, and how should you resolve it?

Quick Answer

The most likely reason BitLocker is not enabling is that the policy is missing the explicit 'Enable full disk encryption' setting and a specified encryption method under the Windows Encryption section of the Endpoint Protection profile. Even when you configure a TPM protector and recovery key escrow to Azure AD, the Intune policy will not trigger the encryption process unless you toggle the "Enable full disk encryption" option and select a method like XTS-AES 128-bit. This is a common trap on the MD-102 exam: candidates assume that configuring protectors and key escrow alone will start encryption, but the policy must explicitly command the device to encrypt. The exam tests your understanding that the Endpoint Protection template requires granular enablement settings, not just security configurations. A reliable memory tip is "No toggle, no encrypt"—if you don't flip the enable switch and choose a cipher, BitLocker stays dormant regardless of other settings.

⚠ Common exam trap

It's easy for candidates to assume configuring TPM protector and recovery key escrow is sufficient to enable BitLocker, but the 'Enable full disk encryption' setting is a separate mandatory toggle that must be explicitly enabled in the policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy is missing the 'Enable full disk encryption' setting or the encryption method is not specified; check the 'Windows Encryption' settings in the profile.

The 'Endpoint Protection' template for Windows 10 and later requires explicit configuration of the 'Enable full disk encryption' setting and the encryption method (e.g., XTS-AES 128-bit) under the 'Windows Encryption' section. Without these settings, the policy does not trigger BitLocker to start encryption on the device, even if other settings like TPM protector and recovery key escrow are configured. The devices are Microsoft Entra ID joined and meet hardware requirements, so the missing encryption enablement is the most likely cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Devices are not hybrid Microsoft Entra ID joined; convert them to hybrid join for BitLocker policy to apply.

    Why it's wrong here

    BitLocker configuration via Intune Endpoint Protection applies to Microsoft Entra ID joined devices without hybrid join, so the join state is not the cause. Hybrid join is required only where on-premises Group Policy or domain-based management must also apply BitLocker settings.

  • ✗

    The policy does not specify a recovery key escrow location; configure it to escrow to Microsoft Entra ID.

    Why it's wrong here

    The Endpoint Protection template's BitLocker settings include recovery key escrow to Microsoft Entra ID by default, so a missing escrow location is not the cause. Specifying escrow matters when using custom OMA-URI or disk encryption policies.

  • ✓

    The policy is missing the 'Enable full disk encryption' setting or the encryption method is not specified; check the 'Windows Encryption' settings in the profile.

    Why this is correct

    The Endpoint Protection template requires the Windows Encryption settings to explicitly enable BitLocker and specify an encryption method; without them, no encryption is enforced. Enabling full disk encryption with the TPM protector and recovery key escrow resolves the failure.

  • ✗

    Devices are not co-managed with Configuration Manager; enable co-management to apply BitLocker policy.

    Why it's wrong here

    Co-management governs which workload authority applies policy; Intune alone can enforce BitLocker on Microsoft Entra ID joined devices, so co-management is unnecessary. It is tempting where Configuration Manager already manages devices, but the stem states Intune management.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MD-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization has a mix of Windows 10 and Windows 11 devices managed by Intune. You need to enforce BitLocker encryption on all devices. Which policy type should you configure?

medium
  • A.Device configuration profile with Administrative Templates.
  • ✓ B.Endpoint Protection profile in Device restrictions.
  • C.Device compliance policy.
  • D.Windows Update ring policy.

Why B: The correct policy type is an Endpoint Protection profile within Device restrictions, because BitLocker settings for Windows 10/11 devices managed by Intune are configured under the 'Windows Encryption' category of an Endpoint Protection profile. This profile directly controls BitLocker drive encryption, including encryption method, recovery key management, and silent encryption enforcement, which is required for the scenario.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.