1. Home
  2. Security Hardening
  3. CIS Microsoft Windows 10 Enterprise Release 1909 V1.8.1 Bl
  4. Ensure ‘Require additional authentication at startup: Allow BitLocker without a compatible TPM’ is set to ‘Enabled: False’

Ensure ‘Require additional authentication at startup: Allow BitLocker without a compatible TPM’ is set to ‘Enabled: False’

Details

This policy setting allows you to configure whether you can use BitLocker without a Trusted Platform Module (TPM), instead using a password or startup key on a USB flash drive. This policy setting is applied when you turn on BitLocker.

The recommended state for this setting is: Enabled: False (unchecked).

Rationale:

TPM without use of a PIN will only validate early boot components and does not require a user to enter any additional authentication information. If a computer is lost or stolen in this configuration, BitLocker will not provide any additional measure of protection beyond what is provided by native Windows authentication unless the early boot components are tampered with or the encrypted drive is removed from the machine.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: False (unchecked):

Computer ConfigurationPoliciesAdministrative TemplatesWindows ComponentsBitLocker Drive EncryptionOperating System DrivesRequire additional authentication at startup: Allow BitLocker without a compatible TPM

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template VolumeEncryption.admx/adml that is included with the Microsoft Windows 7 & Server 2008 R2 Administrative Templates (or newer).

Impact:

A compatible TPM will be required in order to use BitLocker.

Default Value:

True (checked). (Users can use BitLocker without a compatible TPM by using a password or startup key on a USB flash drive.)

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication, System and Communications Protection.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles