Use Strong Device Encryption Settings
Rationale
To strengthen the security of your endpoint device, you can deploy strong device encryption. The encryption is applied to all partitions that can contain user data, for example, browser history or the general configuration directory /wfs.
Instructions
In Setup, go to Security > Device Encryption.
If your device supports TPM 2.0, use it to protect the encryption key:
The TPM+PIN mode is widely supported.
TPM PCR and TPM PCR+PIN are only supported on selected hardware.
For full details, see: Device Encryption in IGEL OS 12