Health-clinic Windows laptops must run BitLocker, and any laptop with encryption off must fail compliance. Which configuration meets that requirement?
Select an answer to reveal the explanation.
Short Explanation
Disk encryption is a lock on the laptop lid, not a tag on a virtual NIC. UEM pushes the BitLocker payload and compliance fails the device if encryption is off. NSX micro-segmentation never turns BitLocker on, and FileVault is a Mac control.
Full Explanation
Workspace ONE UEM delivers encryption settings with a Windows profile payload such as BitLocker and evaluates encryption state with a compliance policy. Devices that report encryption disabled can be marked non-compliant and actioned. NSX-T security groups and micro-segmentation control datacenter traffic, they do not enable volume encryption. FileVault is a macOS technology, and Workspace ONE Access authentication does not encrypt the disk.