Courseiva
Protect devices →hardMultiple Choice

MD-102 Protect devices Practice Question

Your organization uses Microsoft Intune to manage devices. You have a Windows 10 device that is co-managed with Configuration Manager. You need to configure a policy that requires BitLocker encryption. You create a BitLocker policy in Intune and assign it to the device. After 24 hours, BitLocker is not enabled on the device. You verify that the device is online and the policy is assigned. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume Intune policy always applies to enrolled devices, overlooking the co-management workload slider that can block Intune from managing specific workloads like encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The encryption workload is set to Configuration Manager.

In a co-managed environment, workload control determines which management authority (Configuration Manager or Intune) handles specific policies. If the encryption workload is set to Configuration Manager, Intune's BitLocker policy will be ignored, even if assigned and the device is online. This is the most likely reason the policy did not take effect after 24 hours.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The device is not online.

    Why it's wrong here

    The stem already confirms the device is online, so connectivity cannot explain the failure. Co-managed Windows 10 devices route the BitLocker workload to Configuration Manager by default, so an Intune-assigned policy is ignored until that workload slider moves to Intune.

  • ✓

    The encryption workload is set to Configuration Manager.

    Why this is correct

    BitLocker falls under the Endpoint Protection workload in co-management. If that workload's authority remains with Configuration Manager, Intune's BitLocker policy is ignored on the device, so encryption never applies. Shifting the Endpoint Protection workload slider to Intune (or Pilot) resolves this.

  • ✗

    The device is not enrolled in Intune.

    Why it's wrong here

    The device is co-managed and receiving Intune policy, which requires Intune enrolment, so this contradicts the stem. Enrolment would be the answer if the device appeared only in Configuration Manager with no Intune record whatsoever.

  • ✗

    The BitLocker policy is not assigned to the correct group.

    Why it's wrong here

    The stem confirms the policy is already assigned, so group targeting cannot be the cause. Group assignment matters when a policy reaches no devices at all; here the device receives it but a Configuration Manager workload authority still governs BitLocker.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.