Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsIntune does not use a control named exactly Turn On Virtualization Based Security. To reproduce the Group Policy setting, create a Windows 10 and later Settings catalog policy and configure Enable virtualization based security, normally with Require platform security features set to Secure Boot. Add Hypervisor enforced code integrity only after testing Memory Integrity (HVCI), and configure Credential Guard separately.
What the policy enables
Virtualization-based security (VBS) uses the Windows hypervisor to isolate security-sensitive operating-system functions. It is a foundation for several protections, but enabling the foundation does not automatically enable every related feature.
| Control | What it does | How to treat it in Intune |
|---|---|---|
| Enable virtualization based security | Enables the VBS isolation environment. | Set to Enabled for the basic deployment. |
| Hypervisor enforced code integrity (HVCI) | Also called Memory Integrity; checks kernel-mode code inside the isolated environment and can block incompatible drivers. | Pilot separately, then enable if drivers and applications pass testing. |
| Credential Guard | Uses VBS to help protect authentication secrets. | Configure as a separate decision. It is not implied by basic VBS. |
| Require platform security features | Sets the firmware-security requirement for VBS. | Use Secure Boot for most initial deployments; use Secure Boot plus DMA protection only on compatible hardware. |
| UEFI lock | Makes some settings harder to disable locally or remotely. | Leave off during a pilot unless you have a tested firmware and recovery process. |
Microsoft describes these controls and their relationships in its VBS and Memory Integrity guidance.
Prerequisites and scope
The procedure below targets Intune-managed Windows 10 and Windows 11 devices. Available settings, editions and minimum releases vary by individual policy and Windows build; confirm support in the DeviceGuard Policy CSP and VirtualizationBasedTechnology Policy CSP.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- FULL HD IPS DISPLAY - Enjoy vibrant, crystal-clear images with 178-degree wide-viewing angles
- AMD RYZEN 3 30 PROCESSOR - Everyday performance you can count on; Multitask, stream, game casually, and edit photos smoothly with responsive power and vibrant HDR visuals
- ENJOY UP TO 14 HOURS AND 15 MINUTES OF BATTERY LIFE - HP Fast Charge restores battery from 0 to 50% in approximately 45 minutes
- AMD RADEON 610M GRAPHICS - Experience smooth entertainment; Built for streaming and multitasking, enjoy realistic visuals and efficient performance for work and play
- STORAGE AND MEMORY - 512 GB PCIe NVMe M.2 SSD offers fast speed and efficient storage; and 8 GB LPDDR5 RAM memory boosts performance with higher bandwidth
- The device must be enrolled in Intune and checking in.
- For a Secure Boot requirement, firmware must use UEFI and Secure Boot must be enabled. Intune cannot turn on a disabled firmware setting for you.
- Secure Boot plus DMA protection requires compatible hardware and firmware.
- Credential Guard has stricter edition requirements: Microsoft documents it for Enterprise, Education and IoT Enterprise, not Windows Pro.
- Inventory existing Group Policy, Configuration Manager baselines, security baselines, custom OMA-URI profiles and local policies. Two authorities setting the same value can produce conflicts.
- Identify kernel drivers and applications that install VPN, anti-cheat, disk-filter, backup, endpoint-security or other low-level components.
Microsoft notes that newer Intel and AMD processors generally handle Memory Integrity better; older processors may rely more on emulation and show greater performance impact. Virtual machines also need special testing, including nested-virtualization and generation/version considerations.
Choose the deployment design before creating the profile
| Goal | Settings | When to use |
|---|---|---|
| VBS foundation only | Enable virtualization based security = Enabled; Require platform security features = Secure Boot | Safest first pilot for a mixed hardware fleet. |
| VBS plus Memory Integrity | VBS settings above, plus Hypervisor enforced code integrity | After driver, application and workload validation. |
| VBS with stronger firmware requirement | Require platform security features = Secure Boot and DMA protection | Only where hardware supports DMA protection and the requirement is intentional. |
| Credential protection | Configure Credential Guard separately | When the organization has assessed edition eligibility, authentication compatibility and lock implications. |
| Anti-tamper configuration | Use the applicable UEFI-lock option | After recovery has been tested, including firmware access for devices that will not boot. |
Create the Intune Settings catalog policy
- Sign in to the Microsoft Intune admin center.
- Open Devices → Configuration → Create → New policy.
- Choose Windows 10 and later as the platform and Settings catalog as the profile type, then select Create. Microsoft’s endpoint-protection documentation covers this Settings catalog workflow at Endpoint protection for Windows.
- Give the profile a purpose-specific name, such as
Windows - VBS - PilotorWindows - VBS and HVCI - Production. - On Configuration settings, select Add settings. Search for
virtualization based security,Device GuardandVirtualization Based Technology. Microsoft can change the catalog’s grouping or display labels; search terms are more reliable than a remembered folder name. - Set Enable virtualization based security to Enabled.
- Set Require platform security features to Secure Boot for the normal first deployment. Select Secure Boot and DMA protection only for a hardware set that has been validated for DMA protection.
- If the scope includes Memory Integrity, set Hypervisor enforced code integrity to enabled. Keep UEFI lock disabled unless this profile is deliberately implementing a locked configuration.
- Do not select Credential Guard unless that is an explicit, separately approved requirement.
- Assign the profile to a small pilot group, review the settings and select Create. Expand assignments only after device-state validation.
A restart is commonly needed before VBS or HVCI becomes active. Plan a user communication and maintenance window rather than assuming a successful policy check-in means the feature is already running.
Advanced option: deploy the Policy CSP with OMA-URI
Settings catalog is less error-prone for most organizations. Use a custom OMA-URI profile when you need direct CSP control and have verified the target Windows releases.
| Purpose | OMA-URI | Value |
|---|---|---|
| Enable VBS | ./Device/Vendor/MSFT/Policy/Config/DeviceGuard/EnableVirtualizationBasedSecurity |
1 |
| Require platform security | ./Device/Vendor/MSFT/Policy/Config/DeviceGuard/RequirePlatformSecurityFeatures |
1 = Secure Boot; 3 = Secure Boot plus DMA protection |
| HVCI/Memory Integrity | ./Device/Vendor/MSFT/Policy/Config/VirtualizationBasedTechnology/HypervisorEnforcedCodeIntegrity |
1 = enabled with UEFI lock; 2 = enabled without UEFI lock |
The DeviceGuard CSP maps the first URI to the Group Policy setting and its EnableVirtualizationBasedSecurity registry value. The CSP documentation also lists supported editions, releases and platform-security values. Check those details before assigning a custom profile.
Recommended Free Tools
Pilot and stage the rollout
1. Inventory
Collect Windows edition and build, Secure Boot and TPM status, firmware mode, existing policy sources, HVCI and Credential Guard state, hardware models, virtualization use and installed kernel drivers. Include co-managed devices that may still receive Group Policy or Configuration Manager settings.
Rank #2
- Intel Celeron N4120: 4 Cores & Threads, 1.1GHz Base Clock, Up to 2.6GHz Boost Clock, 4MB Cache, Intel UHD Graphics 600. The perfect combination of performance, power consumption, and value helps your device handle multitasking smoothly and reliably with four processing cores to divide up the work.
- 14" HD Display: 14.0-inch diagonal, HD (1366 x 768), micro-edge, anti-glare. See your digital world in a whole new way. Enjoy movies and photos with the great image quality and high-definition detail of 1 million pixels.
- Memory & Storage: 4 GB LPDDR4x & 64 GB eMMC Storage. Adequate high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once. An embedded multimedia card provides reliable flash-based storage.
- Ports:2 x USB 3.0 Type-A,1 x USB 3.0 Type-C,1 x HDMI,1 x Headphone Jack
- Chrome OS: Chromebook is a computer for the way the modern world works, with thousands of apps. Enjoy the seamless simplicity that comes with Google Chrome and Android apps, all integrated into one laptop. It’s fast, simple, and secure.
2. Pilot VBS first
Use a representative group containing new and older OEM models, VPN and endpoint-security users, developers, virtualization workloads and shared devices. Start with VBS enabled, Secure Boot required, no UEFI lock and HVCI disabled unless HVCI itself is the test objective.
3. Run a separate HVCI pilot
Test boot, sign-in, VPN, printing, docking stations, peripherals, virtualization tools, backup and disk-encryption software, EDR/antivirus agents, management agents, Windows Hello and specialized drivers. Record blocked drivers and application failures rather than treating them as ordinary policy errors.
4. Use staged assignments
- IT and security administrators.
- Early adopters.
- One or two validated hardware models.
- Remaining supported hardware.
- An exception group for devices needing remediation.
Exclude known-incompatible devices until a vendor fix or replacement plan exists. Do not combine a security baseline and a custom VBS profile without checking effective settings and conflict reports; Microsoft’s Windows security-baseline reference contains its own VBS and related defaults.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Verify the effective state
On the Windows device
- Open Windows Security → Device security → Core isolation details and inspect Memory integrity.
- Run this PowerShell query:
Get-CimInstance -ClassName Win32_DeviceGuard `
-Namespace rootMicrosoftWindowsDeviceGuard
Review VirtualizationBasedSecurityStatus, SecurityServicesConfigured and SecurityServicesRunning. You can also run msinfo32 and inspect the Virtualization-based security and running security-services entries. These checks show whether Windows actually activated the feature, not merely whether a policy was received.
In Intune
Open the profile and device status, then check whether each device reports Succeeded, Pending, Error or Conflict. Check last check-in time, assignment filters, group membership and overlapping profiles. An Intune success state only confirms policy processing; firmware, hardware, driver or virtualization limitations can still prevent VBS from running.
Rank #3
- Stunning 15.6" FHD IPS Display: Experience crisp 1920x1080 resolution on this 15.6 inch laptop with an IPS panel that delivers wide viewing angles and vivid colors. The narrow-bezel design maximizes screen real estate for comfortable viewing on this Win 11 laptop, whether you're studying or working.
- Celeron J4105 Processor & 256GB SSD: Powered by a reliable Celeron J4105 processor paired with 12GB DDR4 memory and a fast 256GB M.2 SSD. This laptop computer supports SSD expansion up to 2TB and TF card expansion up to 1TB, so your storage grows with your needs. Delivers smooth multitasking for daily productivity.
- AI-Powered Win 11 Laptop: Built-in AI features enhance your productivity with smart assistance for writing, summarizing, and task management. Pre-installed with Win 11 and includes Office 365 subscription. This student laptop is backed by 1-year warranty and 24/7 customer support.
- All-Day 7000mAh Battery & 180° Hinge: The high-capacity 7000mAh battery keeps this laptop powered through long classes or meetings. The 180-degree lay-flat hinge lets you share your screen effortlessly during presentations. This durable laptop computer adapts to your dynamic workflow.
- Versatile Connectivity Hub: Equipped with USB 3.2, Type-C, Mini HDMI, and 3.5mm audio jack to connect all your peripherals. Stay online anywhere with high-speed 5G WiFi and Bluetooth 4.2. This college laptop keeps you connected at home, in the library, or on the go.
Event logs
For HVCI and driver issues, open Applications and Services Logs → Microsoft → Windows → CodeIntegrity → Operational. Microsoft’s HVCI enablement guidance identifies this log as a key troubleshooting source.
Troubleshoot common failures
Intune reports a conflict
Find the effective policy source before changing anything. Compare Settings catalog, endpoint-security profiles, security baselines, custom OMA-URI policies, Group Policy, Configuration Manager baselines and local policy. Remove or exclude the contradictory source; adding another profile with the opposite value usually makes ownership less clear.
Secure Boot is unavailable or disabled
Confirm that the device boots in UEFI mode and that Secure Boot is enabled in firmware. A policy requiring Secure Boot cannot substitute for firmware configuration.
DMA protection is unsupported
Use the Secure Boot-only value on hardware that does not advertise DMA protection. The value 3 is not a universally stronger replacement; it has a hardware prerequisite.
HVCI blocks a driver or breaks an application
- Identify the driver in Windows Security, Device Manager, CodeIntegrity events or the vendor’s diagnostic tools.
- Obtain an updated driver from the OEM or software vendor and test it in the pilot ring.
- Exclude or defer affected devices if no compatible driver exists.
- Do not broadly disable HVCI simply to hide an unresolved compatibility problem.
Microsoft warns that incompatible drivers can prevent Memory Integrity from enabling and, rarely, can contribute to boot failures or blue screens.
Rank #4
- Efficient Performance for Everyday Computing: Powered by Intel N150 processor with up to 3.6 GHz Intel Turbo Boost Technology, 6 MB L3 cache, 4 cores, and 4 threads, this HP laptop delivers responsive performance for web browsing, streaming, document editing, and multitasking. Paired with 4GB LPDDR5 RAM and 128GB UFS storage, it handles daily tasks smoothly. Includes 1-year Microsoft 365 Personal subscription for Word, Excel, PowerPoint, and cloud storage to maximize your productivity.
- 14-Inch HD Micro-Edge Display:Enjoy clear visuals on the 14-inch HD (1366 x 768) anti-glare screen with 250-nit brightness and 62.5% sRGB coverage. The micro-edge bezel delivers a 79% screen-to-body ratio in a compact design. An HP True Vision 720p HD camera with noise reduction and dual-array microphones supports clear video calls, remote work, and online learning.
- Modern Connectivity and Wireless Technology: Stay connected with Wi-Fi 6 (2x2) for faster wireless speeds and Bluetooth 5.4 for seamless pairing with accessories. Versatile port selection includes 1 USB Type-C 10Gbps with DisplayPort 1.2 for external displays, 2 USB Type-A 5Gbps ports for peripherals, 1 HDMI 1.4b port, 1 headphone/microphone combo jack, and 1 multi-format SD media card reader. Connect monitors, transfer files quickly, and expand your workspace with ease.
- All-Day Battery Life and Portable Design: Enjoy up to 11 hours of video playback, 7.5 hours of mixed usage, or 7.5 hours of wireless streaming on a single charge, perfect for students and professionals on the go. Weighing just 3.24 lb and measuring 12.76" x 8.86" x 0.71", this lightweight laptop fits easily in backpacks and bags. The stylish willow green top cover with matte finish and natural silver keyboard deck with vertical brushing pattern offer a modern, professional look.
- AI-Enhanced Productivity: Access Microsoft Copilot instantly with the dedicated Copilot key for faster assistance. AI Noise Reduction filters background sounds and improves voice clarity during calls. Dual speakers provide clear audio, while the full-size natural silver keyboard and HP Imagepad support comfortable typing and navigation.
A virtual machine shows VBS enabled but not running
Check VM generation, Windows support, nested virtualization and the selected platform-security requirement. Microsoft specifically warns that Azure VMs do not support Memory Integrity when Secure Boot plus DMA protection is selected; use the documented Secure Boot-only approach where appropriate.
A device will not boot after HVCI
First disable the Intune, Group Policy or other policies that re-enable VBS or Memory Integrity. Boot into Windows Recovery Environment, open an elevated command prompt and run:
reg add "HKLMSYSTEMCurrentControlSetControlDeviceGuardScenariosHypervisorEnforcedCodeIntegrity" /v "Enabled" /t REG_DWORD /d 0 /f
Restart, remediate or remove the incompatible driver, and only then plan re-enablement. If UEFI lock was used, recovery may also require disabling Secure Boot through UEFI/BIOS before completing the Windows Recovery Environment procedure, so ensure physical or remote-console firmware access exists.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Alternatives and policy ownership
- Group Policy: Computer Configuration → Administrative Templates → System → Device Guard → Turn On Virtualization Based Security. This remains appropriate for traditional Active Directory environments.
- Windows Security: A local administrator or user can open Windows Security → Device security → Core isolation details → Memory integrity. Use this for testing or one-off devices, not centralized enforcement.
- Configuration Manager/co-management: Suitable during a staged migration, provided one authority owns each setting.
- Security baselines: Useful for a broader Microsoft security posture, but review their VBS, Credential Guard and UEFI-lock values before adding a custom profile.
- Application Control: A possible enterprise route where an existing driver-allowlisting and application-control program already governs kernel code.
Intune Plan 1 is the core service used for this policy; Plan 2 or the Intune Suite is not required solely to enable VBS. Check whether an existing Microsoft 365 E3, E5, F1, F3, Business Premium or Enterprise Mobility + Security entitlement already includes Intune before buying a standalone subscription. Licensing and regional availability can change; consult Microsoft’s Intune planning guide and current pricing page.
Frequently Asked Questions
Does enabling VBS automatically enable Memory Integrity?
No. VBS is the isolation foundation. Memory Integrity is HVCI, a separate setting that must be enabled and tested independently.
Best Value
- Designed for mobility with a slim 0.71-inch profile and lightweight 3.24 lb chassis, making it easy to carry between home, office
Does basic VBS enable Credential Guard?
No. Credential Guard has its own policy, edition requirements and lock choices.
Is Windows Pro supported?
Microsoft documents basic VBS support across supported Pro, Enterprise, Education and IoT Enterprise editions, while Credential Guard is documented for Enterprise, Education and IoT Enterprise. Verify the exact Windows release and CSP setting.
Is Secure Boot mandatory?
It is mandatory when Require platform security features is set to Secure Boot or Secure Boot plus DMA protection. The device must have compatible UEFI firmware with Secure Boot enabled.
Should UEFI lock be enabled?
Only after recovery is tested. Locking makes local or remote disablement harder but can require firmware access during recovery.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCan this be applied to Azure virtual machines?
Test the VM configuration carefully. Microsoft warns against selecting Secure Boot plus DMA protection for Azure VMs when deploying Memory Integrity because VBS can appear enabled but not run.
Why does Intune say Succeeded while VBS is not running?
Intune may have processed the setting successfully even though firmware, hardware, drivers or virtualization limitations prevent activation. Verify with Windows Security, msinfo32 and the Win32_DeviceGuard CIM query.
Will VBS reduce performance?
Impact depends on processor, drivers and workload. Microsoft notes that older processors can experience greater impact, so measure representative workloads during the pilot.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




