1.2.4.2.2.18 Set 'Configure TPM startup PIN:' to 'Require startup PIN with TPM'

Information

This policy setting allows you to configure whether BitLocker requires additional authentication each time the
computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM).

Solution

Make sure 'Configure TPM startup key and PIN:' is set to 'Do not allow startup key and PIN with TPM'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5c., 800-53|SC-28(1), CSCv6|13.2, CSCv6|16.11

Plugin: Windows

Control ID: b51688502f5265e4b1a87397abb60f7c132fec9bd8e1c82eb189d0a4c79ba949