mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-17 19:33:37 +00:00
revert PCR4
This commit is contained in:
@ -26,6 +26,3 @@ When this policy is enabled and the hardware is capable of using Secure Boot for
|
||||
|--|--|
|
||||
| **CSP** | Not available |
|
||||
| **GPO** | **Computer Configuration** > **Administrative Templates** > **Windows Components** > **BitLocker Drive Encryption** > **Operating System Drives** |
|
||||
|
||||
> [!NOTE]
|
||||
> To prevent boot manger roll-back attacks, Windows updates released on and after July 2024 changed the default PCR Validation Profile for **UEFI with Secure Boot** from `7, 11` to `4, 7, 11`.
|
||||
|
@ -26,8 +26,6 @@ A platform validation profile consists of a set of PCR indices ranging from 0 to
|
||||
|
||||
> [!NOTE]
|
||||
> When Secure Boot State (PCR7) support is available, the default platform validation profile secures the encryption key using Secure Boot State (PCR 7) and the BitLocker access control (PCR 11).
|
||||
>
|
||||
> To prevent boot manger roll-back attacks, Windows updates released on and after July 2024 changed the default PCR Validation Profile for **UEFI with Secure Boot** from `7, 11` to `4, 7, 11`.
|
||||
|
||||
The following list identifies all of the available PCRs:
|
||||
|
||||
|
Reference in New Issue
Block a user