windows-itpro-docs/windows/client-management/mdm/policy-csp-deviceguard.md
Nicholas Brower 513fef9bc7 Merged PR 2254: adding admx tips, and fixing admx SKU
adding admx tips, and fixing admx SKU; also fixed some anchor links
2017-07-14 21:53:51 +00:00

4.6 KiB

title, description, ms.author, ms.topic, ms.prod, ms.technology, author, ms.date
title description ms.author ms.topic ms.prod ms.technology author ms.date
Policy CSP - DeviceGuard Policy CSP - DeviceGuard maricia article w10 windows nickbrower 07/14/2017

Policy CSP - DeviceGuard

Warning

Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.


DeviceGuard policies

DeviceGuard/EnableVirtualizationBasedSecurity

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark check mark3 check mark3 cross mark cross mark

 

Added in Windows 10, version 1709. Turns on virtualization based security(VBS) at the next reboot. virtualization based security uses the Windows Hypervisor to provide support for security services. Value type is integer. Supported values:

  • 0 (default) - disable virtualization based security
  • 1 - enable virtualization based security

DeviceGuard/LsaCfgFlags

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark check mark3 check mark3 cross mark cross mark

 

Added in Windows 10, version 1709. This setting lets users turn on Credential Guard with virtualization-based security to help protect credentials at next reboot. Value type is integer. Supported values:

  • 0 (default) - (Disabled) Turns off Credential Guard remotely if configured previously without UEFI Lock
  • 1 - (Enabled with UEFI lock) Turns on Credential Guard with UEFI lock
  • 2 - (Enabled without lock) Turns on Credential Guard without UEFI lock

DeviceGuard/RequirePlatformSecurityFeatures

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark check mark3 check mark3 cross mark cross mark

Added in Windows 10, version 1709. Specifies the platform security level at the next reboot. Value type is integer. Supported values:

  • 1 (default) - Turns on VBS with Secure Boot.
  • 3 - Turns on VBS with Secure Boot and direct memory access (DMA). DMA requires hardware support.
 


Footnote:

  • 1 - Added in Windows 10, version 1607.
  • 2 - Added in Windows 10, version 1703.
  • 3 - Added in Windows 10, version 1709.

DeviceGuard policies supported by Microsoft Surface Hub