-
-Measured Boot |
-Required |
-Required |
-Required |
-Measured boot requires TPM 1.2 or 2.0 and UEFI Secure boot. |
-
-
-Bitlocker |
-Required |
-Required |
-Required |
-TPM 1.2 or later required or a removable USB memory device such as a flash drive. |
-
-
-Passport: Domain AADJ Join |
-n/a |
-Required |
-Required |
-Supports both versions of TPM, but requires TPM with HMAC and EK certificate for key attestation support. |
-
-
-Passport: MSA or Local Account |
-n/a |
-Required |
-Required |
-TPM 2.0 is required with HMAC and EK certificate for key attestation support. |
-
-
-Device Encryption |
-n/a |
-Not Required |
-Required |
-TPM 2.0 is required for all InstantGo devices. |
-
-
-Device Guard / Configurable Code Integrity |
-n/a |
-Optional |
-Optional |
- |
-
-
-Credential Guard |
-n/a |
-Required |
-Required |
-For Windows 10, version 1511, TPM 1.2 or 2.0 is highly recommended. If you don't have a TPM installed, Credential Guard will still be enabled, but the keys used to encrypt Credential Guard will not be protected by the TPM. |
-
-
-Device Health Attestation |
-n/a |
-Required |
-Required |
- |
-
-
-Windows Hello |
-n/a |
-Not Required |
-Not Required |
- |
-
-
-UEFI Secure Boot |
-Not Required |
-Not Required |
-Not Required |
- |
-
-
-Platform Key Storage provider |
-n/a |
-Required |
-Required |
- |
-
-
-Virtual Smart Card |
-n/a |
-Required |
-Required |
- |
-
-
-Certificate storage (TPM bound) |
-n/a |
-Required |
-Required |
- |
-
-
-