GPO policy: "Boot-Start Driver Initialization Policy" — Early Launch Anti-Malware (ELAM) policy under Computer Configuration > Administrative Templates > System > Early Launch Antimalware. Controls which boot-start drivers are permitted to initialize based on their ELAM classification. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DriverSearching:DriverLoadPolicy (REG_DWORD). CIS Benchmark (L1) recommends value 3 (Good, unknown, and bad but critical) as a balanced default; some benchmarks recommend value 1 (Good only) for highest assurance. Reference: Policy CSP - ADMX_EarlyLaunch
Values
| Enum Value | Description |
|---|---|
|
|
Good only (registry value 1). Only drivers classified as "Known Good" by ELAM are initialized. Drivers classified as Unknown or Bad are blocked. |
|
|
Good and unknown (registry value 3). Drivers classified as "Known Good" or "Unknown" are initialized; drivers classified as "Bad" are blocked. CIS L1 recommended value. |
|
|
Good, unknown, and bad but critical (registry value 7). Drivers classified as "Bad" are allowed to initialize only if ELAM also flags them as critical to the boot process; non- critical bad drivers are still blocked. |
|
|
All (registry value 255 / 0xFF). All boot-start drivers are initialized regardless of ELAM classification. Least secure; not recommended. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"GOOD_ONLY"