DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Redmond desk9 min

How to Enable Virtualization-Based Security with Microsoft Intune

Deploy VBS through an Intune device-scoped Settings Catalog policy, then reboot and verify that Windows reports it running. Learn how to assess prerequisites, handle HVCI and Credential Guard separately, and troubleshoot failures.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To enable Virtualization-Based Security (VBS) on managed Windows devices, create an Intune Windows 10 and later Settings Catalog profile, set Device Guard > Enable Virtualization Based Security to Enabled, and assign it to a pilot device group. Plan for a reboot, then confirm VBS is running on the endpoint: an Intune success status means the policy was delivered, not necessarily that Windows successfully started VBS.

VBS is the hypervisor-backed security foundation; it does not automatically enable Memory Integrity (HVCI) or Credential Guard. Those controls need their own compatibility review and deployment decisions.

What VBS enables—and what it does not

VBS uses hardware virtualization and the Windows hypervisor to create an isolated environment for selected security functions. The isolation helps protect those functions from compromise of the ordinary Windows kernel. Microsoft describes the architecture and hardware requirements in its VBS overview for OEMs.

Feature What it does Deployment distinction
Virtualization-Based Security (VBS) Provides the hypervisor-backed isolation foundation. Configured with the Device Guard VBS setting.
Hypervisor-Protected Code Integrity (HVCI), or Memory Integrity Uses VBS to protect kernel-mode code integrity and restrict unsafe executable memory. Separate setting; evaluate driver compatibility.
Credential Guard Uses VBS to isolate credential secrets, including LSASS-related secrets. Separate policy choice; edition support and UEFI-lock consequences differ.
Secure Launch Provides hardware-supported boot-integrity protections. Separate Device Guard policy and hardware support apply.
DMA protection Helps protect against certain direct-memory-access attacks. Depends on compatible hardware and configuration.

“Device Guard” remains in policy names and paths, although Microsoft generally refers to the individual protections such as VBS, HVCI, and Credential Guard. Enabling VBS alone does not mean those other protections are enabled. VBS is one layer of endpoint security, not a replacement for Defender, application control, patching, BitLocker, Secure Boot, attack-surface reduction, or identity protections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Check device readiness before assigning the policy

The base Device Guard VBS policy applies to Windows 10 version 1709 and later and supports Pro, Enterprise, Education, and IoT Enterprise editions, including IoT Enterprise LTSC where documented. That is policy applicability, not a guarantee that every device can run VBS. For current deployments, prioritize supported Windows 11 releases; Windows 10 reached end of support on October 14, 2025, though management and support arrangements can vary. Check Microsoft’s DeviceGuard Policy CSP for the setting’s current applicability.

  • Processor: Use a 64-bit processor with virtualization extensions such as Intel VT-x or AMD-V, or an equivalent capability.
  • Firmware and boot: Confirm UEFI and Secure Boot readiness for the features you intend to use, and verify that firmware virtualization is enabled. Requirements vary by feature.
  • Additional protections: Check TPM, Secure Launch, and DMA capabilities where the planned configuration requires them; do not assume every VBS-capable device supports every related feature.
  • Drivers and applications: Inventory storage, graphics, VPN, endpoint-security, backup, virtualization, and other kernel-mode drivers. HVCI can reveal incompatible drivers, so validate representative hardware and software before broad deployment.
  • Virtual machines: A Windows VM needs nested virtualization or Guest VSM support to run VBS. Verify the hypervisor and VM configuration rather than treating a VM like a physical endpoint.
  • Operations: Schedule a reboot window. Policy receipt and runtime activation are separate events.

Create the Intune Settings Catalog profile

Settings Catalog is the clearest general-purpose route for this setting: it exposes the Windows policy without requiring a custom OMA-URI. Portal labels can change, but the current procedure is:

  1. Sign in to the Microsoft Intune admin center, then go to Devices > Windows > Manage devices > Configuration.
  2. Select Create > New policy. Choose Windows 10 and later for Platform and Settings catalog for Profile type.
  3. Give the profile a specific name, such as Windows – Enable VBS – Pilot. Add a description that identifies the intended devices and deployment ring.
  4. Select Add settings, search for Virtualization Based Security, and open the Device Guard category.
  5. Select Enable Virtualization Based Security and set it to Enabled. This is a device-scoped setting, not a user setting. Its Policy CSP path is ./Device/Vendor/MSFT/Policy/Config/DeviceGuard/EnableVirtualizationBasedSecurity; the CSP uses 1 to enable and 0 to disable it.
  6. Configure scope tags if your administrative model uses them. Assign the profile to a pilot device group, review the assignment and settings, then create the policy.

Microsoft documents the setting, CSP path, scope, supported editions, and values in the DeviceGuard Policy CSP. Avoid assigning the same setting through overlapping profiles or management authorities unless you have deliberately designed precedence.

Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
  • 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
  • 4GB DDR4 System Memory; 128GB Solid State Drive
  • 11.6" HD (1366 x 768) Multi-Touch Display
  • Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
  • Windows 11 Pro

Choose separately whether to enable HVCI

If the goal is only to establish the VBS platform, the base VBS setting is the relevant profile setting. If the security goal includes Memory Integrity, configure HVCI separately under Virtualization Based Technology > Hypervisor Enforced Code Integrity. Microsoft documents this Settings Catalog route and the corresponding VirtualizationBasedTechnology Policy CSP. That CSP setting is documented for Windows 11 version 21H2 and later.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
HVCI choice Policy value Operational trade-off
Disabled / remotely reversible 0 Does not enable HVCI.
Enabled with UEFI lock 1 More resistant to remote policy removal, but recovery and reversal are harder.
Enabled without UEFI lock 2 Enables HVCI while allowing a more straightforward remote policy change.

HVCI can improve kernel-mode code integrity, but incompatible drivers may cause application or device problems. Pilot it on representative models and workloads, and resolve driver issues before expanding. Do not choose UEFI lock as a default convenience setting: it trades easier remote reversibility for stronger persistence.

Decide whether Credential Guard belongs in the rollout

Credential Guard is another separate decision, not an automatic consequence of enabling VBS. The DeviceGuard CSP’s Credential Guard setting uses 0 to turn it off remotely when it was configured without UEFI lock, 1 to enable with UEFI lock, and 2 to enable without UEFI lock. Microsoft notes that the LsaCfgFlags setting for Credential Guard is not supported on Windows Pro, even though the base VBS setting supports Pro.

Rank #3
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

UEFI lock has material recovery consequences: an ordinary remote registry or Group Policy change cannot disable a UEFI-locked Credential Guard configuration; clearing the UEFI configuration on each affected device is required. Microsoft explains this limitation in its Endpoint Protection guidance. Pilot Credential Guard independently, including legacy authentication, credential-management tools, support procedures, and the organization’s ability to perform device-level recovery.

Assign in rings and plan for activation

Use a controlled deployment so that incompatibilities and management conflicts are visible before broad assignment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Build a pilot device group. Include representative hardware models, Windows editions, docks, VPN clients, and security software.
  2. Defer sensitive or uncertain devices. Initially exclude break-glass, diagnostic, kiosk, legacy-application, and unsupported devices where disruption would be costly.
  3. Review policy ownership. Look for competing Settings Catalog profiles, Endpoint Protection profiles, security baselines, Group Policy, custom OMA-URI policies, Configuration Manager co-management, or OEM firmware controls.
  4. Start with the intended control. Deploy base VBS first if that is the goal; assess HVCI and Credential Guard as distinct changes rather than silently bundling them.
  5. Allow check-in and schedule a restart. A device checks in, receives the MDM policy, and records configuration; Windows may need a reboot before the hypervisor and VBS services initialize. Microsoft notes reboot-related activation in its Intune Endpoint Protection guidance.
  6. Expand by ring. Move from IT pilot to early adopters, then a business unit, then broader deployment after reviewing endpoint runtime status and compatibility.
  7. Keep exceptions and recovery paths. Maintain a way to pause or exclude affected models, document the rollback procedure, and make an explicit UEFI-lock decision before enabling any locked configuration.

Verify policy delivery in Intune and runtime state in Windows

Use two forms of verification because Intune configuration status and Windows runtime status answer different questions.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

Review Intune status

Open the configuration profile and review its device status and per-setting status. Examine pending, succeeded, error, conflict, and not-applicable results, along with last check-in, assignment/filter results, and any reboot still due. A conflict can indicate another policy source configuring the same setting. A succeeded result confirms policy handling; it does not prove that VBS is running.

Check System Information

  1. Open Start and search for System Information (or run msinfo32).
  2. Open System Summary and inspect Virtualization-based security; confirm it reports Running.
  3. Review the related fields for security properties required and available, configured and running VBS services, Credential Guard, and HVCI where shown.

The fields help distinguish platform capability, configuration, and active services. Do not infer that every related feature is running from the single VBS summary line.

Use PowerShell for inventory

Get-CimInstance -Namespace rootMicrosoftWindowsDeviceGuard -ClassName Win32_DeviceGuard | Format-List *

This query returns Device Guard-related properties that can help with inventory and diagnosis. Interpret status values and service identifiers against Microsoft’s current DeviceGuard documentation; no single numeric property proves that every VBS component is functioning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
15.6 Inch Win 11 Laptop Computer, N4020, 4GB DDR4 RAM, 128GB Storage
  • WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
  • 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
  • 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
  • CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
  • LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.

Confirm Memory Integrity when HVCI is in scope

On devices where HVCI is intended, check Windows Security > Device security > Core isolation where available, and compare that endpoint state with the configured HVCI policy. Microsoft describes Memory Integrity and its relationship to VBS in its Memory Integrity guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot devices that do not reach the expected state

Symptom Likely cause What to check or do
Intune reports success, but VBS is not running Restart is pending, or Windows cannot initialize the hypervisor/security services. Restart after policy receipt, then recheck System Information. If still not running, inspect firmware, boot mode, hypervisor configuration, device capability, and policy conflicts.
VBS is unavailable or cannot start Virtualization extensions are disabled in firmware, hardware lacks required support, or the device is in an unsupported configuration. Confirm 64-bit CPU virtualization support and firmware settings; for a VM, confirm nested virtualization or Guest VSM.
Secure Boot or related security properties are unavailable Firmware or boot configuration does not meet the selected feature’s requirements. Review UEFI/Secure Boot readiness and the specific feature requirements before changing boot configuration; test changes on the affected model first.
HVCI causes a driver or application issue A kernel-mode driver may not be compatible. Identify and update, remove, or otherwise remediate the driver; hold or exclude affected models while testing. Avoid adding UEFI lock during diagnosis.
Credential Guard remains enabled after a remote change It was configured with UEFI lock. Use the documented device-level UEFI recovery process; a routine remote policy change is insufficient.
Intune reports conflict or not applicable Another policy authority may overlap, or the device may not meet setting applicability. Check assignment/filter results, profile per-setting status, edition/version, and competing Group Policy, baseline, Endpoint Protection, OMA-URI, or co-management settings.

Do not assume a universal performance penalty or a universal absence of one: impact depends on processor generation, workload, driver stack, and which protections are enabled. Assess on representative devices before organization-wide rollout.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99
Bestseller No. 2
Dell Latitude 3190 11.6' HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core; 4GB DDR4 System Memory; 128GB Solid State Drive
Bestseller No. 3
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$304.00

Choose the management route that fits the environment

  • Settings Catalog: Best starting point for a focused, discoverable VBS profile and separately selected settings.
  • Windows security baseline: Consider this when the organization wants a broader Microsoft-recommended configuration rather than one isolated control. Microsoft’s current baseline reference includes VBS-related settings and identifies its cited baseline as based on Windows 11 25H2: Windows MDM settings reference. Review the full baseline and its interactions before deployment.
  • Endpoint Protection profile: Useful when related controls such as Credential Guard are being managed as part of a broader endpoint-security configuration; account for overlap with other profiles.
  • Custom OMA-URI: Can target the CSP directly, but is less discoverable and easier to misconfigure. Reserve it for cases where the required setting is unavailable in Settings Catalog or explicit CSP automation is needed.
  • Group Policy: In hybrid or legacy environments, the equivalent policy is Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security. Do not configure the same setting through both Group Policy and Intune without an intentional precedence design.
  • DFCI: On supported OEM devices, firmware management can control CPU and I/O virtualization at the UEFI layer. Availability varies by manufacturer and model; Microsoft warns that incorrect DFCI assignments can make devices difficult to recover. See the DFCI settings reference.

Deployment checklist

  • Confirm Windows version, edition, CPU virtualization capability, firmware readiness, and VM requirements where applicable.
  • Inventory drivers and representative applications before enabling HVCI.
  • Use a device-scoped Settings Catalog assignment for the base VBS policy.
  • Decide separately whether HVCI, Credential Guard, Secure Launch, or DMA protection is required and supported.
  • Document whether any UEFI-locked setting is justified and how physical recovery will work.
  • Deploy through pilot and staged rings with an approved restart window.
  • Check both Intune policy status and Windows runtime state, and maintain exceptions and rollback procedures.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.