GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — enforce user certificate requirement. Controls whether a user certificate (smart card) is required as a protector when enabling BitLocker on fixed data drives. Registry: HKLM\SOFTWARE\Policies\Microsoft\FVE:FDVEnforceUserCert (REG_DWORD). Reference: BitLocker CSP (FixedDrivesRecoveryOptions)
Values
| Enum Value | Description |
|---|---|
|
|
User certificate not required (registry value 0). A smart card / user certificate is not mandatory as a BitLocker protector on fixed data drives. |
|
|
User certificate required (registry value 1). A smart card / user certificate must be used as a BitLocker protector on fixed data drives. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"NOT_REQUIRED"