1. Home
  2. Security Hardening
  3. DISA Windows Server 2016 STIG V2R3
  4. WN16-00-000100 – Windows Server 2016 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use – TPM enabled and ready for use.

WN16-00-000100 – Windows Server 2016 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use – TPM enabled and ready for use.

Details

Credential Guard uses virtualization-based security to protect data that could be used in credential theft attacks if compromised. A number of system requirements must be met in order for Credential Guard to be configured and enabled properly. Without a TPM enabled and ready for use, Credential Guard keys are stored in a less secure method using software.

Solution

Ensure domain-joined systems have a TPM that is configured for use. (Versions 2.0 or 1.2 support Credential Guard.)

The TPM must be enabled in the firmware.

Run ‘tpm.msc’ for configuration options in Windows.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles