GPO policy: "Turn On Virtualization Based Security" — "Select Platform Security Level" sub-option, under Computer Configuration > System > Device Guard. Controls which platform security features are required to run Virtualization Based Security (VBS). Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:RequirePlatformSecurityFeatures (REG_DWORD). Reference: Policy CSP - VirtualizationBasedTechnology
Values
| Enum Value | Description |
|---|---|
|
|
Secure Boot only (registry value 1, default). VBS requires Secure Boot as the platform security baseline. Hardware DMA protection is not mandated. |
|
|
Secure Boot and DMA protection (registry value 3). VBS requires both Secure Boot and hardware-based DMA protection (IOMMU). DMA protection requires hardware support. More secure than Secure Boot alone. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"SECURE_BOOT"