MD-102 Manage and maintain devices Practice Question
Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?
⚠ Common exam trap
It's easy for candidates to assume a configuration profile alone enforces encryption immediately, overlooking the mandatory user interaction step required by macOS for FileVault activation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check if the user has logged in and acknowledged the FileVault prompt.
FileVault encryption on macOS requires user interaction to complete. When Intune deploys a FileVault profile with recovery key escrow, the user must log in and explicitly acknowledge the FileVault prompt to enable encryption. If the user has not done so, the device remains unencrypted regardless of the profile assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check if the user has logged in and acknowledged the FileVault prompt.
Why this is correct
FileVault encryption only starts after the local user authenticates and approves the privacy prompt enabling the secure token; until that acknowledgement occurs, the profile applies but the disk stays unencrypted, so checking user sign-in and prompt acceptance explains the unencrypted devices.
- ✗
Ensure that a compliance policy is also assigned requiring encryption.
Why it's wrong here
A compliance policy only reports or marks non-compliance; it does not trigger FileVault encryption or escrow the recovery key. It is tempting because compliance policies do surface encryption state, but enforcement requires the configuration profile's FileVault payload to actually apply and escrow to Microsoft Entra ID.
- ✗
Ensure the devices are supervised.
Why it's wrong here
Supervision is not required for FileVault enforcement on macOS; it affects other restrictions. It is tempting because supervision gates many iOS configuration payloads, but FileVault escrow to Microsoft Entra ID works on unsupervised Macs, so supervision is not the blocking factor here.
- ✗
Verify that the profile is assigned to the correct device group.
Why it's wrong here
Assignment scope is a valid check, but the stem says only some devices are unencrypted, implying the profile reached the group. The first check should be whether FileVault's escrow setting is configured to Microsoft Entra ID rather than a static key, since escrow failure blocks enforcement.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.