MD-102 Protect devices Practice Question
You are configuring a Microsoft Intune compliance policy for Windows 11 devices. You need to ensure that devices with BitLocker not enabled are marked noncompliant. Which setting should you configure in the compliance policy?
⚠ Common exam trap
Test-takers frequently confuse BitLocker enforcement with other security settings like Secure Boot or TPM, which are related but do not directly check for BitLocker encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require BitLocker
To enforce BitLocker encryption, the compliance policy must include the 'Require BitLocker' setting. This setting directly evaluates whether BitLocker is enabled on the device. Other security settings like Secure Boot or TPM presence do not confirm BitLocker status. Therefore, configuring 'Require BitLocker' ensures devices without encryption are marked noncompliant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require BitLocker
Why this is correct
The 'Require BitLocker' setting in a Windows compliance policy directly checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This setting is specifically designed to enforce encryption at the device level, aligning with security requirements for data protection.
- ✗
Require code integrity
Why it's wrong here
Code integrity is a Windows security feature that validates the integrity of system files and drivers. It is not related to BitLocker encryption. Enabling this requirement would not check for BitLocker status. Thus, it does not meet the scenario's need to enforce BitLocker.
- ✗
Require Trusted Platform Module (TPM)
Why it's wrong here
A TPM is a hardware component often used by BitLocker, but requiring a TPM does not guarantee that BitLocker is enabled. A device can have a TPM but not have BitLocker turned on. This setting alone does not enforce encryption, so it would not mark a device noncompliant for lacking BitLocker.
- ✗
Require Secure Boot
Why it's wrong here
Secure Boot ensures that only trusted software loads during startup, but it does not verify that BitLocker is enabled. A device can have Secure Boot enabled while BitLocker remains off. Therefore, this setting does not enforce drive encryption and would not mark a device noncompliant solely for missing BitLocker.
Go deeper
Related to this question
Learn chapter
Configuring Compliance Policies
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.