Policy
Configure use of smart cards on fixed data drives
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016
This policy setting allows you to specify whether smart cards can be used to authenticate user access to the BitLocker-protected fixed data drives on a computer. If you enable this policy setting smart cards can be used to authenticate user access to the drive. You can require a smart card authentication by selecting the "Require use of smart cards on fixed data drives" check box. Note: These settings are enforced when turning on BitLocker, not when unlocking a drive. BitLocker will allow unlocking a drive with any of the protectors available on the drive. If you disable this policy setting, users are not allowed to use smart cards to authenticate their access to BitLocker-protected fixed data drives. If you do not configure this policy setting, smart cards can be used to authenticate user access to a BitLocker-protected drive.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\Software\Policies\Microsoft\FVE\FDVAllowUserCert | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
Require use of smart cards on fixed data drives ID FDVRequireSmartCard_Name | boolean | HKLM\Software\Policies\Microsoft\FVE\FDVEnforceUserCert Type REG_DWORD | Options: true (1), false (0) True: Set value = 1 · False: Set value = 0 |
Other policies in this category
Explore related policies at the same level.
- ComputerAllow access to BitLocker-protected fixed data drives from earlier versions of WindowsAt least Windows Server 2008 R2 or Windows 7 through Windows Server 2022 or Windows 11 Version 22H2
- ComputerChoose how BitLocker-protected fixed drives can be recoveredAt least Windows Server 2008 R2 or Windows 7
- ComputerConfigure use of hardware-based encryption for fixed data drivesAt least Windows Server 2012 or Windows 8
- ComputerConfigure use of passwords for fixed data drivesAt least Windows Server 2008 R2 or Windows 7
- ComputerDeny write access to fixed drives not protected by BitLockerAt least Windows Server 2008 R2 or Windows 7
- ComputerEnforce drive encryption type on fixed data drivesAt least Windows Server 2012 or Windows 8