---
title: SystemGuardLaunch enum | Wartiva GraphQL API
description: GPO policy: "Turn On Virtualization Based Security" — "Secure Launch Configuration" sub-option, under Computer Configuration > System > Device Guard.
url: https://wartiva.com/api-docs/types/system-guard-launch.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `SystemGuardLaunch` enum

GPO policy: "Turn On Virtualization Based Security" — "Secure Launch Configuration" sub-option, under Computer Configuration > System > Device Guard. Controls whether Windows Defender System Guard Secure Launch (DRTM) is enabled to provide a hardware-rooted boot integrity measurement. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard:ConfigureSystemGuardLaunch (REG_DWORD). Reference: [Policy CSP - VirtualizationBasedTechnology](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-virtualizationbasedtechnology)

## Values

| Enum Value | Description |
|---|---|
| `NOT_CONFIGURED` | Unmanaged / not configured (registry value 0, default). Secure Launch configuration is left to the administrative user's discretion; the policy does not enforce a specific state. |
| `ENABLED` | Secure Launch enabled (registry value 1). Enables Secure Launch if the hardware supports it. Provides hardware-rooted attestation of the boot process. |
| `DISABLED` | Secure Launch disabled (registry value 2). Explicitly disables Secure Launch on this device. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"NOT_CONFIGURED"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
