MD-102 Prepare infrastructure for devices Practice Question
You need to configure Windows 10 devices to automatically encrypt their drives using BitLocker when they enroll in Microsoft Intune. You have created a BitLocker policy in Endpoint Security. However, after enrollment, some devices are not encrypted. You verify that the devices have a TPM 2.0 and meet hardware requirements. What is the most likely reason for the failure?
⚠ Common exam trap
Many candidates assume hardware readiness (TPM, Secure Boot) is sufficient for automatic encryption, but Intune requires explicit recovery key escrow to Azure AD as a gating condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The BitLocker policy does not require a recovery password to be saved to Azure AD.
BitLocker requires a recovery key to be escrowed to Azure AD before encryption can proceed when managed via Intune. If the policy does not mandate saving the recovery password to Azure AD, the encryption process will fail silently on devices that meet all hardware prerequisites, including TPM 2.0. This is a common configuration oversight in Endpoint Security BitLocker policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The devices do not have Secure Boot enabled.
Why it's wrong here
Secure Boot is not a prerequisite for BitLocker.
- ✗
The TPM is not enabled in the BIOS.
Why it's wrong here
If TPM is not enabled, BitLocker would complain, but you verified TPM 2.0.
- ✓
The BitLocker policy does not require a recovery password to be saved to Azure AD.
Why this is correct
Without recovery key escrow, BitLocker may not encrypt.
- ✗
The devices are not compliant with the BitLocker compliance policy.
Why it's wrong here
Compliance policy checks after encryption; it does not prevent encryption.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.