STIGQter STIGQter: STIG Summary: Microsoft Windows 11 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

Windows 11 systems must have a Trusted Platform Module (TPM) enabled.

DISA Rule

SV-253255r1210279_rule

Vulnerability Number

V-253255

Group Title

SRG-OS-000424-GPOS-00188

Rule Version

WN11-00-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure systems have a TPM that is configured for use. (Versions 2.0 supports Credential Guard.)

The TPM must be enabled in the firmware.

Run "tpm.msc" for configuration options in Windows.

Check Contents

Verify the system has a TPM and is ready for use.

Run "tpm.msc".
Review the sections in the center pane.
"Status" must indicate it has been configured with a message such as "The TPM is ready for use" or "The TPM is on and ownership has been taken".
TPM Manufacturer Information - Specific Version = 2.0

If a TPM is not found or is not ready for use, this is a finding.

Vulnerability Number

V-253255

Documentable

False

Rule Version

WN11-00-000010

Severity Override Guidance

Verify the system has a TPM and is ready for use.

Run "tpm.msc".
Review the sections in the center pane.
"Status" must indicate it has been configured with a message such as "The TPM is ready for use" or "The TPM is on and ownership has been taken".
TPM Manufacturer Information - Specific Version = 2.0

If a TPM is not found or is not ready for use, this is a finding.

Check Content Reference

M

Target Key

5471