8.1 (BL) Ensure 'Require Device Encryption' is set to 'Enabled'

Information

This setting allows the Admin to require encryption to be turned on using BitLocker\Device Encryption. Disabling the policy won't turn off the encryption on the system drive. But will stop prompting the user to turn it on.

The recommended state for this setting is: Enabled

Note: Setting this policy to Enabled triggers encryption of all drives (silently or non-silently based on AllowWarningForOtherDiskEncryption policy).

Note #2: Currently only full disk encryption is supported when using this CSP for silent encryption. For non-silent encryption, encryption type will depend on SystemDrivesEncryptionType and FixedDrivesEncryptionType configured on the device.

Encrypting drives on end-user devices helps prevent sensitive data at rest from being read in the event a device is lost or stolen. Enabling this setting is also a requirement to turning encryption on machines silently without prompting the end user.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Bitlocker\Require Device Encryption

See Also

https://workbench.cisecurity.org/benchmarks/21767

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: 744ef0a74362765d475e4003b26cae0eb72c394e697eb040396881cd3205e76b