--- title: Policy CSP - Security description: Policy CSP - Security ms.author: maricia ms.topic: article ms.prod: w10 ms.technology: windows author: nickbrower ms.date: 07/26/2017 --- # Policy CSP - Security > [!WARNING] > Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Specifies whether to allow the runtime configuration agent to install provisioning packages.
The following list shows the supported values: - 0 – Not allowed. - 1 (default) – Allowed. **Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Specifies whether to allow automatic device encryption during OOBE when the device is Azure AD joined.
The following list shows the supported values: - 0 – Not allowed. - 1 (default) – Allowed. **Security/AllowManualRootCertificateInstallation**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Specifies whether the user is allowed to manually install root and intermediate CA certificates.
The following list shows the supported values: - 0 – Not allowed. - 1 (default) – Allowed.
Most restricted value is 0. **Security/AllowRemoveProvisioningPackage**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Specifies whether to allow the runtime configuration agent to remove provisioning packages.
The following list shows the supported values: - 0 – Not allowed. - 1 (default) – Allowed. **Security/AntiTheftMode**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Allows or disallow Anti Theft Mode on the device.
The following list shows the supported values: - 0 – Don't allow Anti Theft Mode. - 1 (default) – Anti Theft Mode will follow the default device configuration (region-dependent). **Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Added in Windows 10, version 1607 to replace the deprecated policy **Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices**.
Specifies whether to allow automatic device encryption during OOBE when the device is Azure AD joined.
The following list shows the supported values: - 0 (default) – Encryption enabled. - 1 – Encryption disabled. **Security/ClearTPMIfNotReady**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Allows enterprise to turn on internal storage encryption.
The following list shows the supported values: - 0 (default) – Encryption is not required. - 1 – Encryption is required.
Most restricted value is 1. > [!IMPORTANT] > If encryption has been enabled, it cannot be turned off by using this policy. **Security/RequireProvisioningPackageSignature**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Specifies whether provisioning packages must have a certificate signed by a device trusted authority.
The following list shows the supported values: - 0 (default) – Not required. - 1 – Required. **Security/RequireRetrieveHealthCertificateOnBoot**
Home | Pro | Business | Enterprise | Education | Mobile | Mobile Enterprise |
---|---|---|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Specifies whether to retrieve and post TCG Boot logs, and get or cache an encrypted or signed Health Attestation Report from the Microsoft Health Attestation Service (HAS) when a device boots or reboots.
The following list shows the supported values: - 0 (default) – Not required. - 1 – Required.
Setting this policy to 1 (Required): - Determines whether a device is capable of Remote Device Health Attestation, by verifying if the device has TPM 2.0. - Improves the performance of the device by enabling the device to fetch and cache data to reduce the latency during Device Health Verification. > [!NOTE] > We recommend that this policy is set to Required after MDM enrollment.
Most restricted value is 1.