Courseiva
Protect devices →easyMultiple Choice

Configuring BitLocker with TPM Protector and Azure AD Recovery Key in Intune

An organization wants to enforce encryption on all Windows 10/11 devices using Intune. Which policy type should they use?

⚠ Common exam trap

A common mix-up: candidates confuse Device compliance policy (which only checks encryption status) with a policy that actually enforces encryption, or they assume the settings catalog is the only way to configure BitLocker, missing the purpose-built Endpoint security disk encryption policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Endpoint security disk encryption policy

The Endpoint security disk encryption policy in Intune is specifically designed to enforce encryption (e.g., BitLocker) on Windows 10/11 devices. It provides a dedicated, streamlined interface for configuring encryption settings and monitoring compliance, unlike general device configuration profiles which require manual setup via the settings catalog. This policy type is the correct choice because it directly targets disk encryption as a security baseline, aligning with the organization's goal to enforce encryption across all managed devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device compliance policy

    Why it's wrong here

    A compliance policy evaluates and reports device state against conditions such as requiring BitLocker, but it does not itself turn encryption on; it marks non-compliant devices and can trigger Conditional Access. It would be correct when the goal is to assess or gate access based on encryption status already configured elsewhere.

  • ✗

    App protection policy

    Why it's wrong here

    App protection policies govern data transfer within and between mobile apps on iOS and Android, applying to app-level containerisation rather than full-disk encryption on Windows. They would be the right choice for restricting copy-paste or save-as in Outlook mobile, not for enforcing BitLocker on Windows 10/11 endpoints.

  • ✗

    Device configuration profile (settings catalog)

    Why it's wrong here

    A settings catalog profile configures Windows Defender Firewall, BitLocker CSP and similar settings, but it does not itself report or enforce device state; the disk encryption requirement is met through the BitLocker configuration here, yet the question asks which policy type enforces encryption compliance. It would be correct for delivering configuration baselines.

  • ✓

    Endpoint security disk encryption policy

    Why this is correct

    Endpoint security disk encryption policies in Intune configure BitLocker settings and silently enable encryption across Windows 10 and 11 devices, including escrowing recovery keys to Microsoft Entra ID. This is the purpose-built policy type for enforcing encryption at scale.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.