---
title: EnforceUserCert enum | Wartiva GraphQL API
description: GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — enforce user certificate requirement.
url: https://wartiva.com/api-docs/types/enforce-user-cert.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `EnforceUserCert` enum

GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — enforce user certificate requirement. Controls whether a user certificate (smart card) is required as a protector when enabling BitLocker on fixed data drives. Registry: HKLM\SOFTWARE\Policies\Microsoft\FVE:FDVEnforceUserCert (REG_DWORD). Reference: [BitLocker CSP (FixedDrivesRecoveryOptions)](https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#fixeddrivesrecoveryoptions)

## Values

| Enum Value | Description |
|---|---|
| `NOT_REQUIRED` | User certificate not required (registry value 0). A smart card / user certificate is not mandatory as a BitLocker protector on fixed data drives. |
| `REQUIRED` | User certificate required (registry value 1). A smart card / user certificate must be used as a BitLocker protector on fixed data drives. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"NOT_REQUIRED"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
