MS-900 · Question #227
A company uses Microsoft 365. The company needs to remotely encrypt devices. You need to identify which solution meets the requirement. Which solution should you choose?
The correct answer is A. Microsoft Intune. Remotely encrypting devices requires a Mobile Device Management (MDM) solution, which Microsoft Intune provides through device configuration policies including BitLocker encryption enforcement.
Question
Options
- AMicrosoft Intune
- BRetention labels
- CAzure Information Protection scanner
- DSensitivity labels
How the community answered
(27 responses)- A78% (21)
- B15% (4)
- C4% (1)
- D4% (1)
Why each option
Remotely encrypting devices requires a Mobile Device Management (MDM) solution, which Microsoft Intune provides through device configuration policies including BitLocker encryption enforcement.
Microsoft Intune is a cloud-based MDM and Mobile Application Management (MAM) solution that can remotely push encryption policies to enrolled devices, such as enforcing BitLocker on Windows or FileVault on macOS. Intune allows administrators to configure device compliance policies and encryption settings that are applied remotely across managed endpoints. This makes it the correct choice for remotely encrypting devices at scale.
Retention labels are used to manage the lifecycle of data in Microsoft 365 services (e.g., SharePoint, Exchange) for compliance purposes, not for encrypting physical or virtual devices.
Azure Information Protection scanner is used to discover, classify, and protect files stored on on-premises file servers and SharePoint, not to encrypt devices remotely.
Sensitivity labels are used to classify and protect documents and emails by applying encryption and access controls to content, not to remotely encrypt entire devices.
Concept tested: Remote device encryption using Microsoft Intune MDM
Source: https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices
Topics
Community Discussion
No community discussion yet for this question.