MD-102 Protect devices Practice Question
Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that BitLocker Drive Encryption is enabled on all devices and that the recovery keys are escrowed to Microsoft Entra ID (Azure AD). Which policy type should you use?
⚠ Common exam trap
Many candidates confuse compliance policies that check for BitLocker with configuration policies that actually enable and escrow keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device configuration profile for endpoint protection
To enable BitLocker and escrow recovery keys to Microsoft Entra ID, you should use a device configuration profile with the endpoint protection settings. This profile allows you to configure BitLocker to silently enable encryption and back up recovery keys to Microsoft Entra ID. Compliance policies only check for encryption, and security baselines may not handle key escrow as directly. App protection policies are unrelated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
App protection policy
Why it's wrong here
App protection policies are used to protect corporate data within apps on mobile devices (iOS/Android) and Windows. They do not manage device encryption or BitLocker settings. They are not applicable to enabling BitLocker or escrowing recovery keys. Therefore, this is incorrect.
- ✗
Security baseline
Why it's wrong here
Security baselines include BitLocker settings and can enforce encryption, but they may not automatically escrow recovery keys to Microsoft Entra ID in all configurations. Security baselines are a set of recommended settings, and while they can include BitLocker, the specific requirement to escrow keys to Microsoft Entra ID is more directly configured via a device configuration profile. Also, security baselines might not be as granular for key escrow.
- ✓
Device configuration profile for endpoint protection
Why this is correct
A device configuration profile with the endpoint protection workload includes BitLocker settings. You can configure BitLocker to silently enable encryption and escrow recovery keys to Microsoft Entra ID. This policy actively enforces the settings on the device. It is the correct choice to both enable BitLocker and ensure key escrow.
- ✗
Device compliance policy
Why it's wrong here
Device compliance policies are used to evaluate the compliance state of devices, such as requiring BitLocker to be enabled. However, they do not enforce the encryption or escrow recovery keys. They only report whether the device meets the requirement. To enable BitLocker and escrow keys, you need a configuration policy that actively sets the encryption and key escrow settings.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.