Are OEMs required to encrypt (Bit Locker) the WS2019 System Drive?

GlennRA 1 Reputation point
2021-05-12T15:31:13.13+00:00

In consideration of a Microsoft post in Redmond Magazine; ...

https://redmondmag.com/articles/2020/06/11/windows-server-hardware-security-requirements.aspx

... , the TPM requirements are pretty clear. However, it seems that drive encryption is only recommended. As an OEM, are we required to encrypt the system drive/volume for those WS2019 pre-installed machines we sell? Additionally, how is any drive encryption requirement addressed for those manufactured/WADK images of WS2019 we respectively sell?

Is there Microsoft documentation on this.

Thanks,

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Teemo Tang 11,471 Reputation points
    2021-05-13T03:01:47.783+00:00

    No, you don’t need to encrypt the system drive/volume for those Windows Server 2019 pre-installed machines, in other words, as an OEM you could choose encrypt or don’t encrypt your preinstalled Server 2016 machines free, there is not a mandatory provision.
    BitLocker drive encryption in Windows 10 for OEMs | Microsoft Learn
    https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-bitlocker

    From the Blog which published by Microsoft Windows Server Team on June 11, 2020, there is not any words mentioned force BitLocker encryption on pre-installed Windows Server system.
    Microsoft raises the security standard for next major Windows Server release - Microsoft Windows Server Blog
    https://cloudblogs.microsoft.com/windowsserver/2020/06/11/microsoft-raises-the-security-standard-for-next-major-windows-server-release/
    Regards

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.