Endpoint configuration · GraphQL enum

HypervisorEnforcedCodeIntegrity enum

GPO policy: "Turn On Virtualization Based Security" — "Virtualization Based Protection of Code Integrity" sub-option, under Computer Configuration > System > Device Guard. Enables Hypervisor- Protected Code Integrity (HVCI), which uses VBS to validate kernel-mode code integrity. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:HypervisorEnforcedCodeIntegrity (REG_DWORD). CIS Benchmark recommends value 1 (enabled with UEFI lock) for highest assurance. Reference: Policy CSP - VirtualizationBasedTechnology

Values

Enum Value Description

DISABLED

HVCI disabled (registry value 0, default). Turns off Hypervisor-Protected Code Integrity remotely if it was previously configured without a UEFI lock.

ENABLED_WITH_UEFI_LOCK

HVCI enabled with UEFI lock (registry value 1). Turns on HVCI and stores the configuration in UEFI firmware. Cannot be disabled without physical access to clear the UEFI variable.

ENABLED_WITHOUT_LOCK

HVCI enabled without UEFI lock (registry value 2). Turns on HVCI but does not store the setting in UEFI firmware. Can be disabled remotely via policy.

NOT_CONFIGURED

HVCI is not configured by policy.

Used by

Example

Example

"DISABLED"