Domain Member: Domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use

b7074672-cbee-4409-a64a-9b03894fcf2f

Credential Guard uses virtualization-based security to protect data that could be used in credential theft attacks if compromised. A number of system requirements must be met in order for Credential Guard to be configured and enabled properly. Without a TPM enabled and ready for use, Credential Guard keys are stored in a less secure method using software.

Remediation

Ensure domain-joined systems have a TPM that is configured for use. (Versions 2.0 or 1.2 support Credential Guard.)

The TPM must be enabled in the firmware.

Run "tpm.msc" for configuration options in Windows.

STIG:
Server
2022: https://system32.eventsentry.com/stig/viewer/V-254246
2019: https://system32.eventsentry.com/stig/viewer/V-205848
2016: https://system32.eventsentry.com/stig/viewer/V-224827

Desktop:
W11: https://system32.eventsentry.com/stig/viewer/V-253255
W10: https://system32.eventsentry.com/stig/viewer/V-220698

CSCv7: 5.1
NIST 800-53 : IA-5, SC-28, CM-6, SI-3
NIST 800-171: 3.5.2, 3.13.3, 3.4.6
CMMC v2.0 L2: IA.L2-3.5.2, SC.L2-3.13.3, CM.L2-3.4.6
PCI-DSS v4.0: 2.2.1, 8.2.1
HIPAA SR : §164.312(a)(1), §164.312(d)
HIPAA HICP : Practice 3 (Identity and Access Management), Practice 4 (Data Protection)