Courseiva

MD-102 Manage and maintain devices Practice Question

You are a Microsoft Intune administrator for Tailwind Traders. The company has enrolled Windows 11 devices. You need to configure BitLocker encryption on all devices using Intune. You have created an endpoint security policy for BitLocker and assigned it to the correct group. After 24 hours, some devices still show as not encrypted. You verify that the devices are compliant with the policy's prerequisites. What should you do to force the policy to apply?

⚠ Common exam trap

MD-102 often tests whether candidates jump to re-enrollment or policy recreation when the correct first step is simply forcing a device sync to trigger pending policy application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remotely sync the devices from the Intune console to refresh policy.

When a BitLocker endpoint security policy is assigned but devices have not applied it, forcing a remote sync from the Intune console triggers the device to check in and apply pending policies, including BitLocker encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Group Policy Editor to configure BitLocker locally on each device.

    Why it's wrong here

    Local Group Policy Editor configures BitLocker on one device only, bypassing Intune management and leaving the assigned endpoint security policy unenforced across the fleet. A remote sync or device restart from the Intune portal triggers policy delivery, which is the correct action when devices have not yet checked in.

  • ✗

    Check if the devices have TPM version 2.0.

    Why it's wrong here

    TPM 2.0 is already confirmed as a satisfied prerequisite in the stem, so rechecking it addresses nothing; the issue is policy delivery, not hardware capability. TPM verification would be the correct step when devices fail BitLocker prerequisites, not when an assigned policy has simply not applied.

  • ✗

    Re-create the BitLocker policy with a different name.

    Why it's wrong here

    Re-creating the policy with a new name produces an identical assignment and does not alter delivery; the original policy is already correctly targeted, so the devices still need to check in. Forcing a sync or restart from Intune is the correct action to trigger policy application on enrolled devices.

  • ✓

    Remotely sync the devices from the Intune console to refresh policy.

    Why this is correct

    Intune applies policy on device check-in, so devices that have not contacted the service since assignment still lack BitLocker settings. Triggering a remote sync forces each device to retrieve and apply the endpoint security policy immediately.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.