Information
This policy setting ensures that all domain-joined systems have a Trusted Platform Module (TPM) enabled and ready for use.
Note: This recommendation does not apply to stand-alone systems.
Credential Guard uses virtualization-based security to protect data that could be used in credential theft attacks if compromised. Several system requirements must be met in order for Credential Guard to be configured and enabled properly. Without a TPM enabled and ready for use, Credential Guard keys are stored in a less secure method using software.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Ensure that domain-joined systems have a TPM that is configured for use. (Versions 2.0 or 1.2 support Credential Guard.)
Execute
tpm.msc
for configuration options in the Windows Operating System.
Impact:
Systems without a Trusted Platform Module (TPM) enabled are not authorized.