8.3 (BL) Ensure 'Allow Warning For Other Disk Encryption: Allow Standard User Encryption' is set to 'Enabled'

Information

This setting allows Admins to enforce 'Require Device Encryption' policy for scenarios where policy is pushed while current logged-on user is non-admin/standard user.

This policy is tied to 'Allow Warning For Other Disk Encryption' policy being set to '0', i.e, Silent encryption is enforced.

If 'Allow Warning For Other Disk Encryption' isn't set, or is set to '1', 'Require Device Encryption' policy won't try to encrypt drive(s) if a standard user is the current logged-on user in the system.

The recommended state for this setting is: Enabled

Enabling this ensures all fixed drives are encrypted regardless of the privileges assigned to the currently logged in user.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Bitlocker\Allow Standard User Encryption

Impact:

Enabling BitLocker on a device with third party encryption may render the device unusable and will require reinstallation of Windows.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: 13d833b1fb86a714ddad86ea0535b0a0276f8cf7720850666ce01816e7a42cd2