--- title: Policy CSP - DeviceGuard description: Policy CSP - DeviceGuard ms.author: maricia ms.topic: article ms.prod: w10 ms.technology: windows author: nickbrower ms.date: 11/01/2017 --- # Policy CSP - DeviceGuard
## DeviceGuard policies
DeviceGuard/EnableVirtualizationBasedSecurity
DeviceGuard/LsaCfgFlags
DeviceGuard/RequirePlatformSecurityFeatures

**DeviceGuard/EnableVirtualizationBasedSecurity**
Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark check mark3 check mark3 cross mark cross mark
[Scope](./policy-configuration-service-provider.md#policy-scope): > [!div class = "checklist"] > * Device
 

Added in Windows 10, version 1709. Turns on virtualization based security(VBS) at the next reboot. virtualization based security uses the Windows Hypervisor to provide support for security services. Value type is integer. Supported values:


**DeviceGuard/LsaCfgFlags**
Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark check mark3 check mark3 cross mark cross mark
[Scope](./policy-configuration-service-provider.md#policy-scope): > [!div class = "checklist"] > * Device
 

Added in Windows 10, version 1709. This setting lets users turn on Credential Guard with virtualization-based security to help protect credentials at next reboot. Value type is integer. Supported values:


**DeviceGuard/RequirePlatformSecurityFeatures**
Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark check mark3 check mark3 cross mark cross mark
[Scope](./policy-configuration-service-provider.md#policy-scope): > [!div class = "checklist"] > * Device
Added in Windows 10, version 1709. Specifies the platform security level at the next reboot. Value type is integer. Supported values:  


Footnote: - 1 - Added in Windows 10, version 1607. - 2 - Added in Windows 10, version 1703. - 3 - Added in Windows 10, version 1709. ## DeviceGuard policies supported by Microsoft Surface Hub - [DeviceGuard/AllowKernelControlFlowGuard](#deviceguard-allowkernelcontrolflowguard)