| Policy | Setting | Comment |
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |
| Select the encryption method for operating system drives: | XTS-AES 256-bit |
| Select the encryption method for fixed data drives: | XTS-AES 256-bit |
| Select the encryption method for removable data drives: | XTS-AES 256-bit |
|
| Policy | Setting | Comment |
| Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) | Enabled | |
| Select the encryption method: | AES 256-bit |
|
| Policy | Setting | Comment |
| Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2) | Enabled | |
| Select the encryption method: | AES 256-bit with Diffuser |
|
| Policy | Setting | Comment |
| Choose how users can recover BitLocker-protected drives (Windows Server 2008 and Windows Vista) | Enabled | |
| Important: To prevent data loss, you must have a way to recover BitLocker encryption keys. If you do not allow both recovery options below, you must enable backup of BitLocker recovery information to AD DS. Otherwise, a policy error occurs. | | Configure 48-digit recovery password: | Require recovery password (default) |
| Configure 256-bit recovery key: | Require recovery key (default) |
| Note: If you do not allow the recovery password and require the recovery key, users cannot turn on BitLocker without saving to USB. | | |
| Policy | Setting | Comment |
| Provide the unique identifiers for your organization | Enabled | |
| BitLocker identification field: | Teleperformance-TPM-Security |
| Allowed BitLocker identification field: | Teleperformance-TPM-Security |
|
| Policy | Setting | Comment |
| Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) | Enabled | |
| Require BitLocker backup to AD DS | Enabled |
| If selected, cannot turn on BitLocker if backup fails (recommended default). | | If not selected, can turn on BitLocker even if backup fails. Backup is not automatically retried. | | Select BitLocker recovery information to store: | Recovery passwords and key packages |
| | A recovery password is a 48-digit number that unlocks access to a BitLocker-protected drive. | | A key package contains a drive's BitLocker encryption key secured by one or more recovery passwords | | Key packages may help perform specialized recovery when the disk is damaged or corrupted. | |