911 Windows laptops received the Workspace ONE UEM BitLocker payload, but encryption compliance still fails because the recovery key did not escrow. What should the security administrator check?
Select an answer to reveal the explanation.
Short Explanation
The disk can be locked while city hall still has no spare key. Escrow the BitLocker recovery key to Workspace ONE UEM and let compliance report that escrow.
Full Explanation
Workspace ONE UEM encryption compliance typically requires both BitLocker enabled and the recovery key successfully escrowed and reported. A payload that encrypts the disk without escrow still fails the compliance check. NSX-T tags, Carbon Black Cloud bypass, and Guest Introspection logs are not the UEM escrow path.