Endpoint configuration · GraphQL enum

CredentialIsolation enum

GPO policy: "Turn On Virtualization Based Security" — "Credential Guard Configuration" sub-option, under Computer Configuration > System > Device Guard. Controls whether Windows Defender Credential Guard (lsaiso.exe) is enabled to protect credentials using Virtualization Based Security. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:LsaCfgFlags (REG_DWORD). CIS Benchmark recommends value 1 (enabled with UEFI lock). Automatically enabled on eligible Windows 11 22H2+ devices. Reference: Configure Windows Defender Credential Guard

Values

Enum Value Description

DISABLED

Credential Guard disabled (registry value 0, default). Turns off Credential Guard remotely if it was previously configured without a UEFI lock.

ENABLED_WITH_UEFI_LOCK

Credential Guard enabled with UEFI lock (registry value 1). Turns on Credential Guard and stores the configuration in UEFI firmware. Cannot be disabled without physical access. CIS L1 recommended value.

ENABLED_WITHOUT_LOCK

Credential Guard enabled without UEFI lock (registry value 2). Turns on Credential Guard but does not store the setting in UEFI firmware. Can be disabled remotely via policy.

NOT_CONFIGURED

Credential Guard is not configured by policy.

Used by

Example

Example

"DISABLED"