106.1.1 Ensure 'Device Health: BitLocker' is set to 'Require'

Information

This policy setting ensures that BitLocker Drive Encryption is active on Windows devices. When this policy is set to require, Intune uses the Windows Health Attestation Service (HAS) to verify that BitLocker is enabled and protecting the operating system volume at the time of device check-in.

The recommended state for this setting is: Require.

Full-disk encryption protects data stored on end-user devices from unauthorized access in the event of loss or theft. Without BitLocker, a threat actor who gains physical access to a device can mount the drive externally and read data in plaintext, bypassing all operating system access controls. BitLocker encryption ensures that data at rest remains protected by a cryptographic key bound to the device's hardware security stack.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To establish the recommended configuration from Microsoft Intune Admin Center:

- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under Device Health, set BitLocker to Require.

Impact:

Devices that do not have BitLocker enabled including devices where encryption was initiated but have not completed will be marked non-compliant. Non-compliant devices may lose access to corporate resources until encryption is confirmed.

See Also

https://workbench.cisecurity.org/benchmarks/27282

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28

Plugin: Windows

Control ID: 3cd65b34200af8ef25421efe8046c7770869de00ea3fca230d0c189423e4a445