Information
This policy setting ensures that a Trusted Platform Module (TPM) is present and functional on Windows devices. When set to require, Intune uses the Windows Health Attestation Service to verify TPM availability. The TPM is a dedicated cryptographic processor that provides hardware-based security functions including secure key storage, device attestation, and boot integrity measurement.
The recommended state for this setting is: Require.
TPM supports several critical security features including BitLocker key protection, Windows Hello for Business credential isolation, and Windows Health Attestation. Without a functioning TPM, devices cannot provide hardware-rooted attestation of their security state, and cryptographic keys used for disk encryption and authentication are not hardware-protected. An attacker who compromises software on a TPM-less device may be able to extract encryption keys or bypass authentication entirely. Requiring a TPM establishes a hardware root of trust on every managed device.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To establish the recommended configuration from Microsoft Intune Admin Center:
- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under System Security\Device Security, set Trusted Platform Module (TPM) to Require.
Impact:
Devices without a TPM 2.0 chip or higher, or where the TPM has been disabled in BIOS/UEFI firmware settings, will be marked non-compliant. Non-compliant devices may lose access to corporate resources until the TPM is confirmed.