Courseiva

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?

⚠ Common exam trap

It's easy for candidates to assume a configuration profile alone enforces encryption immediately, overlooking the mandatory user interaction step required by macOS for FileVault activation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check if the user has logged in and acknowledged the FileVault prompt.

FileVault encryption on macOS requires user interaction to complete. When Intune deploys a FileVault profile with recovery key escrow, the user must log in and explicitly acknowledge the FileVault prompt to enable encryption. If the user has not done so, the device remains unencrypted regardless of the profile assignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check if the user has logged in and acknowledged the FileVault prompt.

    Why this is correct

    FileVault encryption only starts after the local user authenticates and approves the privacy prompt enabling the secure token; until that acknowledgement occurs, the profile applies but the disk stays unencrypted, so checking user sign-in and prompt acceptance explains the unencrypted devices.

  • ✗

    Ensure that a compliance policy is also assigned requiring encryption.

    Why it's wrong here

    A compliance policy only reports or marks non-compliance; it does not trigger FileVault encryption or escrow the recovery key. It is tempting because compliance policies do surface encryption state, but enforcement requires the configuration profile's FileVault payload to actually apply and escrow to Microsoft Entra ID.

  • ✗

    Ensure the devices are supervised.

    Why it's wrong here

    Supervision is not required for FileVault enforcement on macOS; it affects other restrictions. It is tempting because supervision gates many iOS configuration payloads, but FileVault escrow to Microsoft Entra ID works on unsupervised Macs, so supervision is not the blocking factor here.

  • ✗

    Verify that the profile is assigned to the correct device group.

    Why it's wrong here

    Assignment scope is a valid check, but the stem says only some devices are unencrypted, implying the profile reached the group. The first check should be whether FileVault's escrow setting is configured to Microsoft Entra ID rather than a static key, since escrow failure blocks enforcement.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.