MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
Device Name: LAPTOP-1234 Compliance State: Non-compliant Last Check-in: 2026-03-10T14:30:00Z Primary User: user@contoso.com OS: Windows 11 Threat Level: High Jailbroken: No Encryption: Not Encrypted
Refer to the exhibit. A device management report from Microsoft Intune shows a device with non-compliant status. Which action should the administrator take to bring the device into compliance?
⚠ Common exam trap
Watch out — candidates often confuse a non-compliant status with a connectivity or agent issue, and choose 'Force a check-in' instead of addressing the specific missing configuration (BitLocker) that caused the non-compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable BitLocker encryption
The device is marked non-compliant because Intune's compliance policy requires BitLocker encryption on Windows devices. Enabling BitLocker satisfies that policy requirement, allowing the device to report as compliant on its next check-in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable BitLocker encryption
Why this is correct
BitLocker Device Encryption is a required compliance setting in Microsoft Intune for Windows devices. The report shows the device as not encrypted, so enabling BitLocker directly addresses this specific noncompliance by invoking the full volume encryption process, which is often a prerequisite for conditional access policies.
- ✗
Force a check-in
Why it's wrong here
Forcing a check-in triggers the Intune MDM channel to receive the latest policy and report current status, but it does not alter the device's actual configuration. Since the device checked in recently, this action would only refresh telemetry and would not remediate the missing BitLocker encryption flag.
- ✗
Remediate jailbreak status
Why it's wrong here
Jailbreak status is a compliance signal that applies only to mobile platforms like iOS and Android, where root access has been obtained. Windows devices do not have a jailbreak condition; instead, they are evaluated using Device Health Attestation (DHA) for integrity, so this remediation action is irrelevant and would not change the reported noncompliance.
- ✗
Install antivirus software
Why it's wrong here
Installing antivirus software addresses a separate compliance policy that checks for a real-time protection solution, such as Microsoft Defender. The specific noncompliance flagged here is encryption, not antivirus, so this action would remain non-compliant even if antivirus is installed or updated, as the BitLocker setting would still show as failed.
Go deeper
Related to this question
Learn chapter
Windows 365 Cloud PC
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.