Revert "Merged PR 4650: Revert "Updated enable-virtualization-based-protection-of-code-integrity.md"

Revert !4645"
This commit is contained in:
Jason Gerend 2017-11-22 23:37:06 +00:00
parent 1078130757
commit 405750bd75

View File

@ -16,7 +16,7 @@ ms.date: 11/07/2017
- Windows 10 - Windows 10
- Windows Server 2016 - Windows Server 2016
Virtualization-based protection of code integrity (herein refered to as HVCI) is a powerful system mitigation, which leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode processes against the injection and execution of malicious or unverified code. Code integrity checks for kernel-mode memory pages are performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor. Virtualization-based protection of code integrity (herein referred to as HVCI) is a powerful system mitigation, which leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode memory against the injection and execution of malicious or unverified code. Code integrity validation is performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor.
Some applications, including device drivers, may be incompatible with HVCI. Some applications, including device drivers, may be incompatible with HVCI.
This can cause devices or software to malfunction and in rare cases may result in a Blue Screen. Such issues may occur after HVCI has been turned on or during the enablement process itself. This can cause devices or software to malfunction and in rare cases may result in a Blue Screen. Such issues may occur after HVCI has been turned on or during the enablement process itself.
@ -34,7 +34,7 @@ If your device already has a WDAC policy (SIPolicy.p7b), please contact your IT
1. Download the Enable HVCI cabinet file. 1. Download the Enable HVCI cabinet file.
2. Open the cabinet file. 2. Open the cabinet file.
3. Right-click the SIPolicy.p7b file and extract it to the following location: 3. Right-click the SIPolicy.p7b file and extract it. Then move it to the following location:
C:\Windows\System32\CodeIntegrity C:\Windows\System32\CodeIntegrity