Client deployment in batches for a considerable number of systems is a good practice in itself.
Keep these recommendations in mind when managing servers and client systems:
Do not try to create the Drive Encryption deployment task at the root level of your System Tree and activate it. It is a good practice to deploy Drive Encryption to the systems at the sub-level branches.
Do not deploy Drive Encryption to the server systems, especially the server hosting your ePO - On-prem server.
Secure your ePO - On-prem server and database system in the most secured location and keep it accessible for authorized personnel only.