1.2.4.2.2.19 Set 'Configure TPM startup:' to 'Do not allow TPM'

Information

This policy setting allows you to configure whether BitLocker requires additional authentication each time the
computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM).

Solution

Make sure 'Configure TPM startup:' is set to 'Do not allow TPM'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CSCv6|13.2, CSCv6|16.11

Plugin: Windows

Control ID: d20870c60f3c22c46385f4c48a860af5a6ea73fa57106b463063c5a179e4755e