Skip to content

Device Guard and Virtualization Based Security in Windows

Violet edited this page Nov 3, 2023 · 5 revisions

Device GuardDeviceGuardIcon

An AI generated picture of a cat girl working in a server farm


Most of the Device Guard and Virtualization-Based Security features are Automatically enabled by default on capable and modern hardware. The rest of them will be enabled and configured to the most secure state after you apply the Microsoft Security Baselines 23H2 or later.

The Harden Windows Security Module has a feature that is accessible through confirm-SystemCompliance cmdlet. It will let you to scan your system and verify the implementations of the Device Guard policies.


About UEFI Lock

UEFI locked security measures are rooted in Proof of Physical Presence. The Following policies are included in Device Guard


Device Guard Controls and Policies


  1. Standard hardware security not supported
    • This means that your device does not meet at least one of the requirements of Standard Hardware Security.
  2. Your device meets the requirements for Standard Hardware Security.
  3. Your device meets the requirements for Enhanced Hardware Security
  4. Your device has all Secured-core PC features enabled








C#


Clone this wiki locally