To Clarify, in the Full Disk Encryption Policy yes FDE is enabled by default. However, what controls whether the FDE Blade get's installed is based on the Endpoint Installation Package (EPS.msi) you exported from your Endpoint MGMT Server to take an install on your client machines. This could have been the full exported package you created from 'Package for export' or from 'Software Deployment Rules' where you can use our Initial Client (small package) to install of machine and then use software deployment rules to control remotely which software blades those client will get.
As @PhoneBoy explained, we would need some screenshots from your Smart Endpoint Console to see what you have configured. And if it is easier for you, please create a case/SR with our TAC so we can assist further.
Justin Cortez
Technology Leader | Endpoint Cyber Security Products | Americas Endpoint Team