1.2.4.2.2.20 Set 'Configure TPM startup key:' to 'Do not allow startup key with TPM'

Information

This policy setting allows you to configure whether BitLocker requires additional authentication each time the
computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM).

Solution

Make sure 'Configure TPM startup key:' is set to 'Do not allow startup key with TPM'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5c., 800-53|SC-28(1), CSCv6|13.2, CSCv6|16.11

Plugin: Windows

Control ID: 0a3a295346a1780b17293b61fcf3d69185d9ac9062532a0aee68f008a1dd0539