1.2.4.2.2.27 Set 'Allow Secure Boot for integrity validation' to 'Enabled'

Information

This policy setting allows you to configure whether Secure Boot will be allowed as the platform integrity
provider for BitLocker operating system drives.

Solution

Make sure 'Allow Secure Boot for integrity validation' is set to 'Enabled'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-3, CSCv6|13.2

Plugin: Windows

Control ID: 4208dfd5bf198f1295a54a39745ee14c91b5db89c3cedc798fd324750e5672f7