1.2.4.2.2.30 Configure 'Reset platform validation data after BitLocker recovery'

Information

This policy setting controls whether a BitLocker-protected computer that is connected to a trusted wired Local Area
Network (LAN) and joined to a domain can create and use Network Key Protectors on TPM-enabled computers to
automatically unlock the operating system drive when the computer is started.

Solution

Configure this setting in a manner that is consistent with security and operational requirements of your organization.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CSCv6|13.2

Plugin: Windows

Control ID: a4c03e7d171cf435aa985a9f4f653fdef90ea0db0f9ef54b430f6d2c90f61a47