GPO policy: "Turn On Virtualization Based Security" — "Kernel-mode Hardware-enforced Stack Protection" sub-option (Windows 11+), under Computer Configuration > System > Device Guard. Controls whether the hardware-enforced kernel shadow stack (Control-flow Enforcement Technology shadow stack) is active to protect the kernel call stack from ROP attacks. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:ConfigureKernelShadowStacksLaunch (REG_DWORD). Reference: Policy CSP - VirtualizationBasedTechnology
Values
| Enum Value | Description |
|---|---|
|
|
Not configured (registry value 0). Kernel shadow stacks protection state is left to system defaults; policy does not enforce a specific mode. |
|
|
Enabled in enforcement mode (registry value 1). Kernel shadow stacks are active and violations (stack integrity failures) are blocked, preventing the offending operation. |
|
|
Enabled in audit mode (registry value 2). Kernel shadow stacks are active but violations are only logged; execution is not blocked. Use to assess compatibility before enforcing. |
|
|
Kernel shadow stacks disabled (registry value 3). Hardware-enforced kernel stack protection is explicitly turned off on this device. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"NOT_CONFIGURED"