Courseiva
Protect devices →easyMultiple Choice

MD-102 Protect devices Practice Question

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that BitLocker Drive Encryption is enabled on all devices and that the recovery keys are escrowed to Microsoft Entra ID (Azure AD). Which policy type should you use?

⚠ Common exam trap

Many candidates confuse compliance policies that check for BitLocker with configuration policies that actually enable and escrow keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device configuration profile for endpoint protection

To enable BitLocker and escrow recovery keys to Microsoft Entra ID, you should use a device configuration profile with the endpoint protection settings. This profile allows you to configure BitLocker to silently enable encryption and back up recovery keys to Microsoft Entra ID. Compliance policies only check for encryption, and security baselines may not handle key escrow as directly. App protection policies are unrelated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    App protection policy

    Why it's wrong here

    App protection policies are used to protect corporate data within apps on mobile devices (iOS/Android) and Windows. They do not manage device encryption or BitLocker settings. They are not applicable to enabling BitLocker or escrowing recovery keys. Therefore, this is incorrect.

  • ✗

    Security baseline

    Why it's wrong here

    Security baselines include BitLocker settings and can enforce encryption, but they may not automatically escrow recovery keys to Microsoft Entra ID in all configurations. Security baselines are a set of recommended settings, and while they can include BitLocker, the specific requirement to escrow keys to Microsoft Entra ID is more directly configured via a device configuration profile. Also, security baselines might not be as granular for key escrow.

  • ✓

    Device configuration profile for endpoint protection

    Why this is correct

    A device configuration profile with the endpoint protection workload includes BitLocker settings. You can configure BitLocker to silently enable encryption and escrow recovery keys to Microsoft Entra ID. This policy actively enforces the settings on the device. It is the correct choice to both enable BitLocker and ensure key escrow.

  • ✗

    Device compliance policy

    Why it's wrong here

    Device compliance policies are used to evaluate the compliance state of devices, such as requiring BitLocker to be enabled. However, they do not enforce the encryption or escrow recovery keys. They only report whether the device meets the requirement. To enable BitLocker and escrow keys, you need a configuration policy that actively sets the encryption and key escrow settings.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.