106.2.1.2 Ensure 'System Security: Device Security: Trusted Platform Module (TPM)' is set to 'Require'

Information

This policy setting ensures that a Trusted Platform Module (TPM) is present and functional on Windows devices. When set to require, Intune uses the Windows Health Attestation Service to verify TPM availability. The TPM is a dedicated cryptographic processor that provides hardware-based security functions including secure key storage, device attestation, and boot integrity measurement.

The recommended state for this setting is: Require.

TPM supports several critical security features including BitLocker key protection, Windows Hello for Business credential isolation, and Windows Health Attestation. Without a functioning TPM, devices cannot provide hardware-rooted attestation of their security state, and cryptographic keys used for disk encryption and authentication are not hardware-protected. An attacker who compromises software on a TPM-less device may be able to extract encryption keys or bypass authentication entirely. Requiring a TPM establishes a hardware root of trust on every managed device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To establish the recommended configuration from Microsoft Intune Admin Center:

- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under System Security\Device Security, set Trusted Platform Module (TPM) to Require.

Impact:

Devices without a TPM 2.0 chip or higher, or where the TPM has been disabled in BIOS/UEFI firmware settings, will be marked non-compliant. Non-compliant devices may lose access to corporate resources until the TPM is confirmed.

See Also

https://workbench.cisecurity.org/benchmarks/27282

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SC-28, 800-53|SI-16

Plugin: Windows

Control ID: cada98c14b80d07ccc8f5fe9e26bd7e3d04dd18adf157d20cfde82ffc0a48f09