1.2.4.2.3.12 Set 'Configure storage of BitLocker recovery information to AD DS:' to 'Backup recovery passwords and key packages'

Information

This policy setting allows you to control how BitLocker-protected removable data drives are recovered in the
absence of the required credentials.

Solution

Make sure 'Configure storage of BitLocker recovery information to AD DS:' is set to 'Backup recovery passwords and key packages'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-10(6), 800-53|SC-28(1), CSCv6|10.3, CSCv6|13.2

Plugin: Windows

Control ID: 70425c8bb4211b36feb4776e9b1c01f4b4eb5f929644c5aa9bf2697ce677f2b6