What does HRESULT 0x80310074 (FVE_E_POLICY_USER_CERT_MUST_BE_HW) mean?

 
Previous Next
FVE_E_POLICY_USER_CERTIFICATE_REQUIRED FVE_E_POLICY_USER_CONFIGURE_FDV_AUTOUNLOCK_NOT_ALLOWED

FVE_E_POLICY_USER_CERT_MUST_BE_HW

FVE_E_POLICY_USER_CERT_MUST_BE_HW The effective policy requires the user-certificate protector to be backed by hardware, such as a smart card. A software-backed certificate does not satisfy that policy even when it otherwise appears valid.

What to check

  • Check whether the selected certificate’s private key is backed by the required hardware token.
  • Confirm that the user is using the certificate template and enrollment path approved for hardware-backed BitLocker protectors.
  • Use a compliant smart-card-based protector instead of trying to bypass the policy with a software certificate.
manage-bde -protectors -get <drive>

Microsoft: Configure BitLocker policy settings

Microsoft: manage-bde -protectors

Microsoft: manage-bde


Looking for a different code? Search another status or error code.