Deny write access to fixed drives not protected by BitLocker

This policy setting determines whether BitLocker protection is required for fixed data drives to be writable on a computer. This policy setting is applied when you turn on BitLocker.If you enable this policy setting all fixed data drives that are not BitLocker-protected will be mounted as read-only. If the drive is protected by BitLocker it will be mounted with read and write access.If you disable or do not configure this policy setting all fixed data drives on the computer will be mounted with read and write access.

Policy path: 

Windows Components\BitLocker Drive Encryption\Fixed Data Drives

Scope: 

Machine

Supported on: 

At least Windows Server 2008 R2 or Windows 7

Registry settings: 

HKLM\System\CurrentControlSet\Policies\Microsoft\FVE!FDVDenyWriteAccess

Filename: 

VolumeEncryption.admx

Related content