Skip to main content

BitLocker

Win - OIB - ES - Encryption - D - BitLocker (OS Disk) - v3.7

CMMC Control Mapping Matrix

NameValue
Basics
NameWin - OIB - ES - Encryption - D - BitLocker (OS Disk) - v3.7
Description
Profile typeSettings catalog
CategoryDisk encryption
Policy typeBitLocker
Platform supportedWindows 10 and later
CreatedThursday, February 26, 2026 5:31:54 AM
Last modifiedThursday, February 26, 2026 5:31:54 AM
Scope tagsDefault
Table 5. Basics - Win - OIB - ES - Encryption - D - BitLocker (OS Disk) - v3.7
NameValue
Administrative Templates
Operating System Drives
Enforce drive encryption type on operating system drivesEnabled
Select the encryption type: (Device)Full encryption
Require additional authentication at startupEnabled
Configure TPM startup key and PIN:Do not allow startup key and PIN with TPM
Configure TPM startup PIN:Do not allow startup PIN with TPM
Configure TPM startup:Require TPM
Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)False
Configure TPM startup key:Do not allow startup key with TPM
Disallow standard users from changing the PIN or passwordEnabled
Choose how BitLocker-protected operating system drives can be recoveredEnabled
Omit recovery options from the BitLocker setup wizardTrue
Allow data recovery agentFalse
Configure storage of BitLocker recovery information to AD DS:Store recovery passwords and key packages
Do not enable BitLocker until recovery information is stored to AD DS for operating system drivesTrue
Save BitLocker recovery information to AD DS for operating system drivesTrue
Configure user storage of BitLocker recovery information:Require 48-digit recovery password
Do not allow 256-bit recovery key
BitLocker Drive Encryption
Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)Enabled
Select the encryption method for removable data drives:AES-CBC 256-bit
Select the encryption method for fixed data drives:XTS-AES 256-bit
Select the encryption method for operating system drives:XTS-AES 256-bit
BitLocker
Require Device EncryptionEnabled
Allow Warning For Other Disk EncryptionDisabled
Allow Standard User EncryptionEnabled
Configure Recovery Password RotationRefresh on for Entra ID-joined devices
Table 6. Settings - Win - OIB - ES - Encryption - D - BitLocker (OS Disk) - v3.7

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.