STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2025 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Windows Server 2025 systems must have a Trusted Platform Module (TPM) enabled and ready for use.

DISA Rule

SV-277993r1212171_rule

Vulnerability Number

V-277993

Group Title

SRG-OS-000780-GPOS-00240

Rule Version

WN25-00-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure systems have a TPM that is configured for use. (Version 2.0 supports Credential Guard.)

The TPM must be enabled in the firmware.

Run "tpm.msc" for configuration options in Windows.

Check Contents

Verify the system has a TPM and it is ready for use.

Run "tpm.msc".

Review the sections in the center pane.

"Status" must indicate it has been configured with a message such as "The TPM is ready for use" or "The TPM is on and ownership has been taken".

TPM Manufacturer Information - Specific Version = 2.0

If a TPM is not found or is not ready for use, this is a finding.

Vulnerability Number

V-277993

Documentable

False

Rule Version

WN25-00-000090

Severity Override Guidance

Verify the system has a TPM and it is ready for use.

Run "tpm.msc".

Review the sections in the center pane.

"Status" must indicate it has been configured with a message such as "The TPM is ready for use" or "The TPM is on and ownership has been taken".

TPM Manufacturer Information - Specific Version = 2.0

If a TPM is not found or is not ready for use, this is a finding.

Check Content Reference

M

Target Key

5719