Courseiva
Prepare infrastructure for deviceshardMultiple ChoiceObjective-mapped

MD-102 Prepare infrastructure for devices Practice Question

You need to configure Windows 10 devices to automatically encrypt their drives using BitLocker when they enroll in Microsoft Intune. You have created a BitLocker policy in Endpoint Security. However, after enrollment, some devices are not encrypted. You verify that the devices have a TPM 2.0 and meet hardware requirements. What is the most likely reason for the failure?

⚠ Common exam trap

Many candidates assume hardware readiness (TPM, Secure Boot) is sufficient for automatic encryption, but Intune requires explicit recovery key escrow to Azure AD as a gating condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The BitLocker policy does not require a recovery password to be saved to Azure AD.

BitLocker requires a recovery key to be escrowed to Azure AD before encryption can proceed when managed via Intune. If the policy does not mandate saving the recovery password to Azure AD, the encryption process will fail silently on devices that meet all hardware prerequisites, including TPM 2.0. This is a common configuration oversight in Endpoint Security BitLocker policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The devices do not have Secure Boot enabled.

    Why it's wrong here

    Secure Boot is not a prerequisite for BitLocker.

  • The TPM is not enabled in the BIOS.

    Why it's wrong here

    If TPM is not enabled, BitLocker would complain, but you verified TPM 2.0.

  • The BitLocker policy does not require a recovery password to be saved to Azure AD.

    Why this is correct

    Without recovery key escrow, BitLocker may not encrypt.

  • The devices are not compliant with the BitLocker compliance policy.

    Why it's wrong here

    Compliance policy checks after encryption; it does not prevent encryption.

About these practice questions

Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.