mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 13:27:23 +00:00
Merge branch 'main' into vp-csp-2307
This commit is contained in:
commit
4a498e4dfb
@ -46,6 +46,8 @@ This policy is intended to provide more security against external DMA capable de
|
||||
|
||||
Device memory sandboxing allows the OS to use the I/O Memory Management Unit (IOMMU) of a device to block unallowed I/O, or memory access by the peripheral. In other words, the OS assigns a certain memory range to the peripheral. If the peripheral attempts to read/write to memory outside of the assigned range, the OS blocks it.
|
||||
|
||||
This policy requires a system reboot to take effect.
|
||||
|
||||
This policy only takes effect when Kernel DMA Protection is supported and enabled by the system firmware. Kernel DMA Protection is a platform feature that can't be controlled via policy or by end user. It has to be supported by the system at the time of manufacturing. To check if the system supports Kernel DMA Protection, check the Kernel DMA Protection field in the Summary page of MSINFO32.exe.
|
||||
<!-- DeviceEnumerationPolicy-Editable-End -->
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user