BitLocker and FIPS 140-2 Compliance and Recovery Keys in AD

Clint 21 Reputation points
2020-07-24T11:54:03.993+00:00

Greetings,

Pre-Windows 8.1 days, if you enabled the FIPS compliance GPO, you weren't allowed to create and back-up the recovery password to AD by design due to security reasons or something along those lines.

Anyway, that was apparently addressed with Windows 8.1 and onward. However, what I haven't been able to confirm is would it now be OK to back up the BitLocker recovery passwords to AD and still be FIPS 140-2 compliant regarding BitLocker?

I haven't been able to find a clear answer on that. Thanks for your time.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,839 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jenny Feng 14,101 Reputation points
    2020-07-27T02:52:58.443+00:00

    Hi,

    "Microsoft validates cryptographic modules on a representative sample of hardware configurations running Windows 10 and Windows Server. It is common industry practice to accept this FIPS 140-2 validation when an environment uses hardware, which is similar to the samples used for the validation process."

    More information please refer to the following article:
    https://learn.microsoft.com/en-us/windows/security/threat-protection/fips-140-validation
    https://learn.microsoft.com/en-us/microsoft-365/compliance/offering-fips-140-2?view=o365-worldwide

    Hope above information can help you.

    0 comments No comments