This commit is contained in:
Paolo Matarazzo
2023-10-05 08:32:04 -04:00
parent 8137ceb43a
commit b20a53a7c7
6 changed files with 35 additions and 105 deletions

View File

@ -9,14 +9,14 @@ ms.topic: include
With this policy you can configure an encryption algorithm and key cipher strength for fixed data drives, operating system drives, and removable data drives individually.
Recommended settings:
Recommended settings: `XTS-AES` alhorithm for all drives. The choice of key size, 128 bit or 256 bit depends on the performance of the device. For more performant hard drives and CPU, choose 256 bit key, for less performant ones use 128.
- For fixed and operating system drives: `XTS-AES` algorithm
- For removable drives: `AES-CBC 128-bit` or `AES-CBC 256-bit`
> [!IMPORTANT]
> Key size might be required by regulators or industry.
If you disable or do not configure this policy setting, BitLocker uses the default encryption method of `XTS-AES 128-bit`.
> [!WARNING]
> [!NOTE]
> This policy doesn't apply to encrypted drives. Encrypted drives utilize their own algorithm, which is set by the drive during partitioning.
| | Path |