Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

In Microsoft Intune, the Allows or disallows FIPS algorithm policy setting configures Windows’ FIPS policy at the device level. Set it to Allow to apply the CSP value 1, or Block to apply 0. Leave it Not configured when Intune should not manage the setting.

Enabling it does not automatically make every application, service, or endpoint FIPS 140 compliant. It affects relevant Windows cryptographic components, while application compliance depends on the cryptographic modules and operating modes used by each product. See Microsoft’s explanation of Windows FIPS 140 validation.

What this Intune setting controls

The Intune setting corresponds to the Windows security policy named System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing. Depending on the catalog presentation, Intune may display it as Allows or disallows FIPS algorithm policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The underlying Windows Policy CSP setting is:

./Device/Vendor/MSFT/Policy/Config/Cryptography/AllowFipsAlgorithmPolicy

Microsoft documents this setting in the Cryptography Policy CSP.

#1 Best Overall
Lenovo Laptop V15, AMD Ryzen 3 7320U, 16GB DDR5, 512GB SSD, Windows 11 Pro
  • EXCEPTIONAL BUSINESS VALUE - The Lenovo V15 combines a sleek design, dependable everyday performance, and MIL-STD-810H tested durability with business-ready security features. Offering many of the essential business capabilities of the ThinkPad E16 at a more affordable price, it's an ideal choice for professionals, students, and small businesses.
  • POWERFUL PERFORMANCE - Powered by the AMD Ryzen 3 7320U processor with integrated AMD Radeon 610M Graphics, this laptop delivers responsive performance for everyday computing. Combined with 16GB LPDDR5 5500MHz memory for smooth multitasking and 512GB PCIe NVMe M.2 SSD for fast boot-ups, quick file access, and ample storage, it keeps your workflow efficient from start to finish.
  • IMMERSIVE VISUAL EXPERIENCE - Enjoy sharp, vibrant visuals on the 15.6" FHD (1920 × 1080) anti-glare display, designed for comfortable viewing during work or entertainment. HDMI and USB-C support up to two external 4K monitors at 60Hz without a docking station, providing an expanded workspace for efficient multitasking. An HD webcam with a privacy shutter ensures clear video calls while protecting your privacy when the camera is not in use.
  • VERSATILE CONNECTIVITY - Stay connected with one USB-C port supporting Power Delivery and DisplayPort 1.2, two USB-A ports, HDMI 1.4, Ethernet (RJ-45), and an audio combo jack for seamless connections to monitors, peripherals, and wired networks. A full-size keyboard with a Numeric Keypad enhances data entry and everyday productivity, while built-in Wi-Fi 6 and Bluetooth 5.3 deliver fast, stable wireless connectivity for work, streaming, and daily use.
  • OPERATING SYSTEM - Preinstalled with Windows 11 Pro 64-bit and AI Copilot, this system delivers a modern, intuitive user experience with advanced security and productivity features. Built-in tools such as BitLocker encryption, Remote Desktop, and enhanced device management help protect data and simplify system administration. Seamless compatibility with a wide range of applications, peripherals, and business software ensures reliable performance for everyday computing.
Intune value CSP value Meaning
Allow 1 Enables the FIPS algorithm policy.
Block 0 Disables or blocks the FIPS algorithm policy.
Not configured Not managed by Intune Intune does not change the setting.

The CSP lists 0 as the default value, but Not configured is not the same management state as explicitly assigning Block. With Not configured, another policy, local configuration, or device management method may determine the effective result.

Device scope, not user scope

This is a device-scoped policy. The ./Device/ prefix in the CSP path reflects that scope. It is not designed to provide different FIPS behavior for individual users on the same Windows device.

Supported Windows versions and editions

Microsoft lists the policy as supported beginning with Windows 10, version 1607, build 10.0.14393. The listed editions include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Windows Pro
  • Windows Enterprise
  • Windows Education
  • Windows IoT Enterprise
  • Windows IoT Enterprise LTSC

These are the Windows client-policy applicability details documented by Microsoft; they are not a blanket guarantee that every Windows Server workload or Microsoft product behaves identically. Confirm the target edition and build in your environment, since Intune catalog availability and applicability filters can change.

How to configure the policy in Intune

  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices.
  3. Select Manage devices, then Configuration.
  4. Select Create > New policy.
  5. For Platform, select Windows 10 and later.
  6. For Profile type, select Settings catalog.
  7. Select Create, enter a policy name and description, and continue to Configuration settings.
  8. Select Add settings.
  9. Search for FIPS, FIPS algorithm, or System cryptography. If the search experience exposes CSP names, also try AllowFipsAlgorithmPolicy.
  10. Select the device-scoped FIPS policy setting.
  11. Choose Allow to enable it or Block to disable it.
  12. Complete scope tags and assignments, review the policy, and select Create.

Microsoft’s Settings Catalog documentation describes the current profile workflow and the Add settings search experience. Microsoft’s Settings Catalog walkthrough shows the same core navigation.

Which value should you choose?

Choose Allow when Windows FIPS mode is an explicit requirement

Select Allow when a documented organizational security baseline, contract, security authority, or application requirement specifically calls for Windows FIPS mode. This sends the integer value 1 through the Policy CSP.

Rank #2
Lenovo V15 Gen 4 Business Laptop, 15.6" FHD Display, Intel Core i5-13420H (Beat i7-1355U), HDMI, RJ45, Webcam, Numeric Keypad, Wi-Fi, Windows 11 Pro, Black (16GB RAM | 512GB SSD)
  • [High Speed RAM And Enormous Space] 4GB high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once; 128GB PCIe NVMe M.2 Solid State Drive allows to fast bootup and data transfer
  • [Processor] Intel Core i5-13420H Processor (8 Cores, 12 Threads, 12MB Intel Smart Cache, Base at 1.5 GHz, Up to 4.6 GHz Max Turbo Frequency), with Intel UHD Graphics
  • [Display] 15.6" FHD (1920 x 1080) Display
  • [Tech Specs] 1 x USB 3.0 Type-A, 1 x USB 2.0 Type-A, 1 x USB Type-C, 1 x HDMI, 1 x RJ45, 1 x headphone/microphone combo, Webcam, Numeric Keypad, Wi-Fi and Bluetooth
  • [Operating System] Windows 11 Pro - Organize open apps with pre-configured layouts to optimize productivity, Navigate with more intuitive experience to get things done, Collaborate with teams with more features

Choose Block to explicitly disable the policy

Select Block when Intune should actively set the Windows policy to disabled. This sends 0. It can be useful when a known policy must be removed from a device population or when you are deliberately standardizing the state across management channels.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose Not configured when Intune should not own the setting

Use Not configured when another management method, such as Group Policy, is authoritative or when the organization has not decided to manage this Windows policy through Intune. Removing the setting from the profile stops Intune from changing or updating it; it does not necessarily erase every locally effective configuration.

FIPS mode is not the same as FIPS 140 compliance

This is the most important qualification for the setting. Windows FIPS mode is an operating-system configuration that applies to relevant Windows cryptographic components, principally the Cryptographic Primitives Library and the Kernel Mode Cryptographic Primitives Library.

FIPS 140 validation, by contrast, is formal validation of a specific cryptographic module under the applicable validation program. Microsoft publishes validation information for particular Windows releases and modules, including its Windows 11 validated modules.

Enabling this Intune policy does not prove that:

  • Every installed application uses a validated cryptographic module.
  • Every application operates that module in its approved mode.
  • Third-party libraries are validated.
  • The entire endpoint or service satisfies a particular compliance framework.

An application may use its own cryptographic library, provider, or configuration. Application and service vendors must establish whether their products use an appropriately validated module and follow its approved security policy. If compliance evidence is required, obtain written confirmation tied to the product version, module, certificate, and operating mode.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Deploy it safely with a pilot

Do not assign this policy globally simply because FIPS sounds more secure. Enabling it can reveal compatibility problems in software that requests unsupported algorithms, uses a nonvalidated provider, or has its own FIPS implementation.

Rank #3
HP New 15.6 inch Laptop Computer, 2025/2026 Edition, Intel High-Performance 4 cores N100 CPU, 16GB RAM, 512GB SSD, Long Battery Life, Ultra-Quiet Design, Windows 11 Pro with Microsoft Office
  • 【Display】The 15.6" 250nits Non-Touch Anti-glare, 45% NTSC LED display has a thin bezel and 85% screen-to-body ratio, which provides a comfortable viewing space for your videos, photos, and documents. Paired with Intel UHD Graphics, making the display colors more vivid and delicate
  1. Identify the exact requirement. Determine whether the requirement is Windows FIPS mode, use of approved algorithms, FIPS 140 validation, or a specific contractual or regulatory control.
  2. Inventory cryptographic dependencies. Include VPN clients, authentication systems, certificate workflows, browsers, backup agents, middleware, custom applications, and integrations.
  3. Create a small device pilot. Use a representative mix of Windows editions, builds, hardware, network paths, and application roles.
  4. Assign to a device group. Because the setting is device-scoped, a device group is generally the clearest assignment target.
  5. Test business workflows. Check sign-in, certificates, TLS connections, VPN access, backups, remote administration, application startup, and data-protection operations.
  6. Expand in rings. Increase the assignment gradually after reviewing help-desk incidents and application-owner results.
  7. Prepare rollback. Keep an exclusion or rollback group and document whether rollback means assigning Block or removing Intune management, depending on the intended authority.

How to verify deployment

Check Intune reporting

After the device checks in, review the profile’s assignment and device configuration status. Check per-setting status, applicability messages, errors, and conflicts. Settings Catalog reporting can help identify whether the setting succeeded on a device or is being overridden or conflicted by another policy.

Also confirm the device’s last Intune check-in. A profile can be correctly assigned while the endpoint has not yet received it.

Verify the effective Windows state

Use more than one source of evidence:

  • Review the applied Windows security policy locally.
  • Check the resulting Windows policy or registry state where appropriate for the organization’s Windows build and management channel.
  • Collect and review MDM diagnostic logs if Intune reports an error or the device remains stale.
  • Test applications that perform cryptographic operations instead of treating policy application as proof of application compliance.

A single local value or PowerShell result should not be treated as universally authoritative without confirming that it reflects the effective policy on the organization’s Windows versions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common problems

The setting cannot be found

  • Confirm that the profile uses Windows 10 and later and Settings catalog.
  • Search for FIPS, FIPS algorithm, and System cryptography, not only the full conversational label.
  • Check that you are creating a device configuration profile rather than a compliance policy.
  • Look for catalog naming or category changes and confirm the underlying CSP name when available.
  • Review the device edition and applicability filters.

Intune reports a conflict

Look for another Settings Catalog profile, a security baseline, an administrative-template profile, a custom OMA-URI profile, or Active Directory Group Policy targeting the same Windows policy or CSP node. Co-managed devices are especially likely to have overlapping authorities. Use per-setting reporting to identify the conflicting profile, then define one authoritative configuration source.

Intune succeeds but an application fails

First establish that the policy applied successfully. Then investigate the application’s cryptographic implementation. It may use a third-party library, request an algorithm rejected under the configured mode, require a vendor-specific FIPS build, or maintain a separate cryptographic setting. Consult the product documentation and vendor rather than assuming the Intune policy itself failed.

“FIPS enabled” is being used as compliance evidence

Separate device-configuration evidence from compliance evidence. The Intune report can show that the Windows policy was assigned and applied. It cannot, by itself, demonstrate that every application uses a validated module in an approved mode or that the organization meets a particular control.

Rank #4
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Group Policy and other configuration options

Active Directory Group Policy

The mapped Group Policy setting is:

Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Group Policy is usually the natural fit for traditionally domain-managed devices with established on-premises governance. Avoid configuring the same policy independently in Group Policy and Intune unless the precedence and ownership model are documented.

Custom OMA-URI

If the Settings Catalog entry is unavailable or unsuitable, a custom profile can target the CSP directly:

./Device/Vendor/MSFT/Policy/Config/Cryptography/AllowFipsAlgorithmPolicy

Use an integer data type with:

1  # enable
0  # disable

The Settings Catalog is preferable when it exposes the setting because it is easier to discover and maintain and generally provides clearer administrative reporting.

Local policy and application-specific settings

Local Group Policy or Local Security Policy can help diagnose an unmanaged device, but they are not scalable enterprise-management methods. Some applications also require their own FIPS mode, validated provider, or approved module. Configure those products according to their vendor documentation; Windows policy alone may be insufficient.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Decision checklist

  • Is there a documented requirement for Windows FIPS mode?
  • Does the requirement specify FIPS 140 validation or a particular module and certificate?
  • Have application owners confirmed compatibility?
  • Is Intune, Group Policy, or another CSP profile the authoritative management channel?
  • Has a representative device pilot completed successfully?
  • Are policy conflicts, monitoring, and rollback documented?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.