Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteTo enable Virtualization-Based Security (VBS) on managed Windows devices, create an Intune Windows 10 and later Settings Catalog profile, set Device Guard > Enable Virtualization Based Security to Enabled, and assign it to a pilot device group. Plan for a reboot, then confirm VBS is running on the endpoint: an Intune success status means the policy was delivered, not necessarily that Windows successfully started VBS.
VBS is the hypervisor-backed security foundation; it does not automatically enable Memory Integrity (HVCI) or Credential Guard. Those controls need their own compatibility review and deployment decisions.
What VBS enables—and what it does not
VBS uses hardware virtualization and the Windows hypervisor to create an isolated environment for selected security functions. The isolation helps protect those functions from compromise of the ordinary Windows kernel. Microsoft describes the architecture and hardware requirements in its VBS overview for OEMs.
| Feature | What it does | Deployment distinction |
|---|---|---|
| Virtualization-Based Security (VBS) | Provides the hypervisor-backed isolation foundation. | Configured with the Device Guard VBS setting. |
| Hypervisor-Protected Code Integrity (HVCI), or Memory Integrity | Uses VBS to protect kernel-mode code integrity and restrict unsafe executable memory. | Separate setting; evaluate driver compatibility. |
| Credential Guard | Uses VBS to isolate credential secrets, including LSASS-related secrets. | Separate policy choice; edition support and UEFI-lock consequences differ. |
| Secure Launch | Provides hardware-supported boot-integrity protections. | Separate Device Guard policy and hardware support apply. |
| DMA protection | Helps protect against certain direct-memory-access attacks. | Depends on compatible hardware and configuration. |
“Device Guard” remains in policy names and paths, although Microsoft generally refers to the individual protections such as VBS, HVCI, and Credential Guard. Enabling VBS alone does not mean those other protections are enabled. VBS is one layer of endpoint security, not a replacement for Defender, application control, patching, BitLocker, Secure Boot, attack-surface reduction, or identity protections.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Check device readiness before assigning the policy
The base Device Guard VBS policy applies to Windows 10 version 1709 and later and supports Pro, Enterprise, Education, and IoT Enterprise editions, including IoT Enterprise LTSC where documented. That is policy applicability, not a guarantee that every device can run VBS. For current deployments, prioritize supported Windows 11 releases; Windows 10 reached end of support on October 14, 2025, though management and support arrangements can vary. Check Microsoft’s DeviceGuard Policy CSP for the setting’s current applicability.
- Processor: Use a 64-bit processor with virtualization extensions such as Intel VT-x or AMD-V, or an equivalent capability.
- Firmware and boot: Confirm UEFI and Secure Boot readiness for the features you intend to use, and verify that firmware virtualization is enabled. Requirements vary by feature.
- Additional protections: Check TPM, Secure Launch, and DMA capabilities where the planned configuration requires them; do not assume every VBS-capable device supports every related feature.
- Drivers and applications: Inventory storage, graphics, VPN, endpoint-security, backup, virtualization, and other kernel-mode drivers. HVCI can reveal incompatible drivers, so validate representative hardware and software before broad deployment.
- Virtual machines: A Windows VM needs nested virtualization or Guest VSM support to run VBS. Verify the hypervisor and VM configuration rather than treating a VM like a physical endpoint.
- Operations: Schedule a reboot window. Policy receipt and runtime activation are separate events.
Create the Intune Settings Catalog profile
Settings Catalog is the clearest general-purpose route for this setting: it exposes the Windows policy without requiring a custom OMA-URI. Portal labels can change, but the current procedure is:
- Sign in to the Microsoft Intune admin center, then go to Devices > Windows > Manage devices > Configuration.
- Select Create > New policy. Choose Windows 10 and later for Platform and Settings catalog for Profile type.
- Give the profile a specific name, such as Windows – Enable VBS – Pilot. Add a description that identifies the intended devices and deployment ring.
- Select Add settings, search for Virtualization Based Security, and open the Device Guard category.
- Select Enable Virtualization Based Security and set it to Enabled. This is a device-scoped setting, not a user setting. Its Policy CSP path is
./Device/Vendor/MSFT/Policy/Config/DeviceGuard/EnableVirtualizationBasedSecurity; the CSP uses1to enable and0to disable it. - Configure scope tags if your administrative model uses them. Assign the profile to a pilot device group, review the assignment and settings, then create the policy.
Microsoft documents the setting, CSP path, scope, supported editions, and values in the DeviceGuard Policy CSP. Avoid assigning the same setting through overlapping profiles or management authorities unless you have deliberately designed precedence.
Rank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
Choose separately whether to enable HVCI
If the goal is only to establish the VBS platform, the base VBS setting is the relevant profile setting. If the security goal includes Memory Integrity, configure HVCI separately under Virtualization Based Technology > Hypervisor Enforced Code Integrity. Microsoft documents this Settings Catalog route and the corresponding VirtualizationBasedTechnology Policy CSP. That CSP setting is documented for Windows 11 version 21H2 and later.
| HVCI choice | Policy value | Operational trade-off |
|---|---|---|
| Disabled / remotely reversible | 0 |
Does not enable HVCI. |
| Enabled with UEFI lock | 1 |
More resistant to remote policy removal, but recovery and reversal are harder. |
| Enabled without UEFI lock | 2 |
Enables HVCI while allowing a more straightforward remote policy change. |
HVCI can improve kernel-mode code integrity, but incompatible drivers may cause application or device problems. Pilot it on representative models and workloads, and resolve driver issues before expanding. Do not choose UEFI lock as a default convenience setting: it trades easier remote reversibility for stronger persistence.
Decide whether Credential Guard belongs in the rollout
Credential Guard is another separate decision, not an automatic consequence of enabling VBS. The DeviceGuard CSP’s Credential Guard setting uses 0 to turn it off remotely when it was configured without UEFI lock, 1 to enable with UEFI lock, and 2 to enable without UEFI lock. Microsoft notes that the LsaCfgFlags setting for Credential Guard is not supported on Windows Pro, even though the base VBS setting supports Pro.
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
UEFI lock has material recovery consequences: an ordinary remote registry or Group Policy change cannot disable a UEFI-locked Credential Guard configuration; clearing the UEFI configuration on each affected device is required. Microsoft explains this limitation in its Endpoint Protection guidance. Pilot Credential Guard independently, including legacy authentication, credential-management tools, support procedures, and the organization’s ability to perform device-level recovery.
Assign in rings and plan for activation
Use a controlled deployment so that incompatibilities and management conflicts are visible before broad assignment.
- Build a pilot device group. Include representative hardware models, Windows editions, docks, VPN clients, and security software.
- Defer sensitive or uncertain devices. Initially exclude break-glass, diagnostic, kiosk, legacy-application, and unsupported devices where disruption would be costly.
- Review policy ownership. Look for competing Settings Catalog profiles, Endpoint Protection profiles, security baselines, Group Policy, custom OMA-URI policies, Configuration Manager co-management, or OEM firmware controls.
- Start with the intended control. Deploy base VBS first if that is the goal; assess HVCI and Credential Guard as distinct changes rather than silently bundling them.
- Allow check-in and schedule a restart. A device checks in, receives the MDM policy, and records configuration; Windows may need a reboot before the hypervisor and VBS services initialize. Microsoft notes reboot-related activation in its Intune Endpoint Protection guidance.
- Expand by ring. Move from IT pilot to early adopters, then a business unit, then broader deployment after reviewing endpoint runtime status and compatibility.
- Keep exceptions and recovery paths. Maintain a way to pause or exclude affected models, document the rollback procedure, and make an explicit UEFI-lock decision before enabling any locked configuration.
Verify policy delivery in Intune and runtime state in Windows
Use two forms of verification because Intune configuration status and Windows runtime status answer different questions.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Review Intune status
Open the configuration profile and review its device status and per-setting status. Examine pending, succeeded, error, conflict, and not-applicable results, along with last check-in, assignment/filter results, and any reboot still due. A conflict can indicate another policy source configuring the same setting. A succeeded result confirms policy handling; it does not prove that VBS is running.
Check System Information
- Open Start and search for System Information (or run
msinfo32). - Open System Summary and inspect Virtualization-based security; confirm it reports Running.
- Review the related fields for security properties required and available, configured and running VBS services, Credential Guard, and HVCI where shown.
The fields help distinguish platform capability, configuration, and active services. Do not infer that every related feature is running from the single VBS summary line.
Use PowerShell for inventory
Get-CimInstance -Namespace rootMicrosoftWindowsDeviceGuard -ClassName Win32_DeviceGuard | Format-List *
This query returns Device Guard-related properties that can help with inventory and diagnosis. Interpret status values and service identifiers against Microsoft’s current DeviceGuard documentation; no single numeric property proves that every VBS component is functioning.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Confirm Memory Integrity when HVCI is in scope
On devices where HVCI is intended, check Windows Security > Device security > Core isolation where available, and compare that endpoint state with the configured HVCI policy. Microsoft describes Memory Integrity and its relationship to VBS in its Memory Integrity guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot devices that do not reach the expected state
| Symptom | Likely cause | What to check or do |
|---|---|---|
| Intune reports success, but VBS is not running | Restart is pending, or Windows cannot initialize the hypervisor/security services. | Restart after policy receipt, then recheck System Information. If still not running, inspect firmware, boot mode, hypervisor configuration, device capability, and policy conflicts. |
| VBS is unavailable or cannot start | Virtualization extensions are disabled in firmware, hardware lacks required support, or the device is in an unsupported configuration. | Confirm 64-bit CPU virtualization support and firmware settings; for a VM, confirm nested virtualization or Guest VSM. |
| Secure Boot or related security properties are unavailable | Firmware or boot configuration does not meet the selected feature’s requirements. | Review UEFI/Secure Boot readiness and the specific feature requirements before changing boot configuration; test changes on the affected model first. |
| HVCI causes a driver or application issue | A kernel-mode driver may not be compatible. | Identify and update, remove, or otherwise remediate the driver; hold or exclude affected models while testing. Avoid adding UEFI lock during diagnosis. |
| Credential Guard remains enabled after a remote change | It was configured with UEFI lock. | Use the documented device-level UEFI recovery process; a routine remote policy change is insufficient. |
| Intune reports conflict or not applicable | Another policy authority may overlap, or the device may not meet setting applicability. | Check assignment/filter results, profile per-setting status, edition/version, and competing Group Policy, baseline, Endpoint Protection, OMA-URI, or co-management settings. |
Do not assume a universal performance penalty or a universal absence of one: impact depends on processor generation, workload, driver stack, and which protections are enabled. Assess on representative devices before organization-wide rollout.
Quick Recap
Choose the management route that fits the environment
- Settings Catalog: Best starting point for a focused, discoverable VBS profile and separately selected settings.
- Windows security baseline: Consider this when the organization wants a broader Microsoft-recommended configuration rather than one isolated control. Microsoft’s current baseline reference includes VBS-related settings and identifies its cited baseline as based on Windows 11 25H2: Windows MDM settings reference. Review the full baseline and its interactions before deployment.
- Endpoint Protection profile: Useful when related controls such as Credential Guard are being managed as part of a broader endpoint-security configuration; account for overlap with other profiles.
- Custom OMA-URI: Can target the CSP directly, but is less discoverable and easier to misconfigure. Reserve it for cases where the required setting is unavailable in Settings Catalog or explicit CSP automation is needed.
- Group Policy: In hybrid or legacy environments, the equivalent policy is Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security. Do not configure the same setting through both Group Policy and Intune without an intentional precedence design.
- DFCI: On supported OEM devices, firmware management can control CPU and I/O virtualization at the UEFI layer. Availability varies by manufacturer and model; Microsoft warns that incorrect DFCI assignments can make devices difficult to recover. See the DFCI settings reference.
Deployment checklist
- Confirm Windows version, edition, CPU virtualization capability, firmware readiness, and VM requirements where applicable.
- Inventory drivers and representative applications before enabling HVCI.
- Use a device-scoped Settings Catalog assignment for the base VBS policy.
- Decide separately whether HVCI, Credential Guard, Secure Launch, or DMA protection is required and supported.
- Document whether any UEFI-locked setting is justified and how physical recovery will work.
- Deploy through pilot and staged rings with an approved restart window.
- Check both Intune policy status and Windows runtime state, and maintain exceptions and rollback procedures.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




