We have enabled all required settings (Secure Boot, VT-x and VT-d, UEFI). By default, Virtualization based security is in running state in windows 11, after enabling the device guard status is changed to enabled but not running which is incorrect. It is happened after enabling the device guard.
Below are the value of VirtualizationBasedSecurityStatus
VirtualizationBasedSecurityStatus
This field indicates whether VBS is enabled and running.
Value Description
- VBS isn't enabled.
- VBS is enabled but not running.
- VBS is enabled and running.
Current Value : 1. VBS is enabled but not running.
Expected Value : 2. VBS is enabled and running.
When we enable Device Guard , in Event Viewer below lines are getting logged.
"Virtualization-based security (policies: VBS Enabled,VSM Required,Secure Boot,Iommu Protection,Mmio Nx,Strong MSR Filtering,Hvci,Boot Chain Signer Soft Enforced) is disabled due to VBS initialization failure with status: The request is not supported."
"The virtualization-based security enablement policy check at phase 0 failed with status: The request is not supported."
Referred Microsoft Article:
https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity
Please please help us in enabling virtualization based security as running after enabling device guard.
Machine info: Windows 11 Enterprise
Version: 21H2
OS build : 22000.1455