Microsoft Windows 10 Bitlocker and FIPS 140-2 compliance

Pete H 1 Reputation point
2021-01-29T16:15:59.777+00:00

Hello,

We have been unable to obtain a clear answer from Microsoft on this question. Was hoping someone in this community has some insight.

Is Microsoft Bitlocker on a Windows 10 computer FIPS 140-2 compliant out of the box (without any additional system changes)?

Additional color to the question: In the Local Security Policy of Windows 10 (secpol) there is a setting:

Security Settings --> Local Policies --> Security Options --> System Cryptography: Use FIPS compliant algorithms for encryption, hashing and signing.

Does this policy need to be enabled for Bitlocker to be FIPS 140-2 compliant, or is Bitlocker on it's own FIPS 140-2 compliant without the need to enable this policy?

If you know the answer, can you point me to a document that clearly states this for Windows 10 Enterprise? We have found some documentation but it's old - 2014 and seems to apply to older versions of Windows, not Windows 10.

Thanks,
Pete

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,754 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AliceYang-MSFT 2,081 Reputation points
    2021-02-01T07:12:40.04+00:00

    Hi,

    BitLocker is FIPS 140-2 validated. Please check the link for more information about FIPS 140-2 Validation.

    FIPS 140 compliant is an industry term for IT products that rely on FIPS 140 validated products for cryptographic functionality.

    System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing can enable FIPS mode. After this policy is enabled, BitLocker will use only FIPS compliant algorithms. BitLocker is FIPS compliant with this policy enabled.

    We recommend that customers hoping to comply with FIPS 140-2 research the configuration settings of applications and protocols they may be using to ensure their solutions can be configured to utilize the FIPS 140-2 validated cryptography provided by Windows when it is operating in FIPS 140-2 approved mode.

    Please also check this link You shouldn’t enable this setting unless you work in government or need to test how software will behave on government PCs.

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.