mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-14 14:27:22 +00:00
Revert "Merged PR 4650: Revert "Updated enable-virtualization-based-protection-of-code-integrity.md"
Revert !4645"
This commit is contained in:
parent
1078130757
commit
405750bd75
@ -16,7 +16,7 @@ ms.date: 11/07/2017
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
- Windows Server 2016
|
- Windows Server 2016
|
||||||
|
|
||||||
Virtualization-based protection of code integrity (herein refered to as HVCI) is a powerful system mitigation, which leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode processes against the injection and execution of malicious or unverified code. Code integrity checks for kernel-mode memory pages are performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor.
|
Virtualization-based protection of code integrity (herein referred to as HVCI) is a powerful system mitigation, which leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode memory against the injection and execution of malicious or unverified code. Code integrity validation is performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor.
|
||||||
|
|
||||||
Some applications, including device drivers, may be incompatible with HVCI.
|
Some applications, including device drivers, may be incompatible with HVCI.
|
||||||
This can cause devices or software to malfunction and in rare cases may result in a Blue Screen. Such issues may occur after HVCI has been turned on or during the enablement process itself.
|
This can cause devices or software to malfunction and in rare cases may result in a Blue Screen. Such issues may occur after HVCI has been turned on or during the enablement process itself.
|
||||||
@ -34,7 +34,7 @@ If your device already has a WDAC policy (SIPolicy.p7b), please contact your IT
|
|||||||
|
|
||||||
1. Download the Enable HVCI cabinet file.
|
1. Download the Enable HVCI cabinet file.
|
||||||
2. Open the cabinet file.
|
2. Open the cabinet file.
|
||||||
3. Right-click the SIPolicy.p7b file and extract it to the following location:
|
3. Right-click the SIPolicy.p7b file and extract it. Then move it to the following location:
|
||||||
|
|
||||||
C:\Windows\System32\CodeIntegrity
|
C:\Windows\System32\CodeIntegrity
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user