1.2.4.2.2.19 Set 'Configure TPM startup:' to 'Do not allow TPM'

Information

This policy setting allows you to configure whether BitLocker requires additional authentication each time the
computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM).

Solution

Make sure 'Configure TPM startup:' is set to 'Do not allow TPM'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CSCv6|13.2, CSCv6|16.11

Plugin: Windows

Control ID: 7de3fc0d4753d830062f5bd6fce7c9493e6f25b07412e7f45b84bdef1b57a64f