GPO policy: "Turn On Virtualization Based Security" — "Virtualization Based Protection of Code Integrity" sub-option, under Computer Configuration > System > Device Guard. Enables Hypervisor- Protected Code Integrity (HVCI), which uses VBS to validate kernel-mode code integrity. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:HypervisorEnforcedCodeIntegrity (REG_DWORD). CIS Benchmark recommends value 1 (enabled with UEFI lock) for highest assurance. Reference: Policy CSP - VirtualizationBasedTechnology
Values
| Enum Value | Description |
|---|---|
|
|
HVCI disabled (registry value 0, default). Turns off Hypervisor-Protected Code Integrity remotely if it was previously configured without a UEFI lock. |
|
|
HVCI enabled with UEFI lock (registry value 1). Turns on HVCI and stores the configuration in UEFI firmware. Cannot be disabled without physical access to clear the UEFI variable. |
|
|
HVCI enabled without UEFI lock (registry value 2). Turns on HVCI but does not store the setting in UEFI firmware. Can be disabled remotely via policy. |
|
|
HVCI is not configured by policy. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"DISABLED"