WN22-00-000090 - Windows Server 2022 systems must have a Trusted Platform Module (TPM) enabled and ready for use.

Information

Credential Guard uses virtualization-based security to protect data that could be used in credential theft attacks if compromised. A number of system requirements must be met for Credential Guard to be configured and enabled properly. Without a TPM enabled and ready for use, Credential Guard keys are stored in a less secure method using software.

Solution

Ensure systems have a TPM that is configured for use. (Version 2.0 supports Credential Guard.)

The TPM must be enabled in the firmware.

Run 'tpm.msc' for configuration options in Windows.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2022_V2R10_STIG.zip