FIPS Compliance with Already Encrypted Drives

Hare, Mike 21 Reputation points
2021-04-22T19:20:41.54+00:00

We have Windows 10 systems already encrypted with BitLocker. I want to get them FIPS compliant. I know I have to set the security policy "System cryptography: Use FIPS compliant algorithms for encryption, hashing and signing." Once that is set, what do I need to do to get these systems FIPS compliant? Do I need to decrypt and re-encrypt them or is there a method to get these systems compliant without having to go through decryption?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,765 questions
{count} votes

Accepted answer
  1. Jenny Feng 14,081 Reputation points
    2021-04-23T01:58:40.987+00:00

    @Hare, Mike
    Hi,
    I'm afraid you need to decrypt and re-encrypt them.
    BitLocker is FIPS-validated, but it requires a setting before encryption that ensures that the encryption meets the standards set forth by FIPS 140-2.

    -Open Local Security Policy as administrator
    -Navigate to Local Policies => Security Options
    -Set System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing to be Enabled
    -Then, encrypt the machine using BitLocker

    According to this article you will only have to decrypt if your changing the method BitLocker recovery.
    https://learn.microsoft.com/zh-cn/archive/blogs/askcore/how-to-make-your-existing-bitlocker-encrypted-environment-fips-complaint
    Hope above information can help you.

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful