GPO policy: "Turn On Virtualization Based Security" — "Secure Launch Configuration" sub-option, under Computer Configuration > System > Device Guard. Controls whether Windows Defender System Guard Secure Launch (DRTM) is enabled to provide a hardware-rooted boot integrity measurement. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:ConfigureSystemGuardLaunch (REG_DWORD). Reference: Policy CSP - VirtualizationBasedTechnology
Values
| Enum Value | Description |
|---|---|
|
|
Unmanaged / not configured (registry value 0, default). Secure Launch configuration is left to the administrative user's discretion; the policy does not enforce a specific state. |
|
|
Secure Launch enabled (registry value 1). Enables Secure Launch if the hardware supports it. Provides hardware-rooted attestation of the boot process. |
|
|
Secure Launch disabled (registry value 2). Explicitly disables Secure Launch on this device. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"NOT_CONFIGURED"