106.1.2 Ensure 'Device Health: Secure Boot' is set to 'Require'

Information

This policy setting ensures that Secure Boot is enabled on Windows devices. When the policy is set to require, Intune uses the Windows Health Attestation Service to verify that the device's firmware has Secure Boot enabled and that the boot chain from UEFI firmware to OS loader to kernel has not been tampered with.

The recommended state for this setting is: Require.

Secure Boot can prevent unauthorized or malicious code from loading during the boot process. Without Secure Boot, attackers can install bootkits or rootkits that persist below the operating system, surviving reimages and making detection by traditional security tools extremely difficult. Secure Boot ensures only digitally signed and trusted bootloaders, OS files, and drivers are permitted to execute during startup.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To establish the recommended configuration from Microsoft Intune Admin Center:

- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under Device Health, set Secure Boot to Require.

Impact:

Devices that do not have Secure Boot enabled will be marked non-compliant. Non-compliant devices may lose access to corporate resources until Secure Boot is confirmed.

See Also

https://workbench.cisecurity.org/benchmarks/27291

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16

Plugin: Windows

Control ID: de81c82f8191e0ec7eaad2aaec4d67314d29da8e8a9689b4af87d96ab7c61585