1.2.4.2.3.11 Set 'Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' to 'False'

Information

This policy setting allows you to control how BitLocker-protected removable data drives are recovered in the
absence of the required credentials.

Solution

Make sure 'Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'False'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-10(6), 800-53|SC-28(1), CSCv6|10.3, CSCv6|13.2

Plugin: Windows

Control ID: 6f2f3f577d6e8b233431ce9684b2e3c30201fc0baed2fb41b4ef478e8423a6d1