Windows 11 System Guard - Firmware Protection - DMA Protection

Romulo Romero 1 Reputation point
2022-04-10T19:26:37.68+00:00

Hi,
I have Memory Integrity and Microsoft Defender Credential Guard enabled on my Windows 11, but I am unable to set the System Guard enabled even having a compatible hardware Tpm 2.0. So far, I have a few clues where the problem might lie, and I am hoping someone can assist me with that. So here are a few audited events:

Kernel Boot:

  • Windows system integrity policy does not allow to load the required system file \EFI\Microsoft\Boot\CiPolicies\Active\
    {CDD5CB55-DB68-4D71-AA38-3DF2B6473A52}.cip with error status 0xC0E90002.
  • System Guard enabled but not supported. Reason: SMX is not supported.
  • System
    • Provider
    [ Name] Microsoft-Windows-Kernel-Boot
    [ Guid] {15ca44ff-4d7a-4baa-bba5-0998955e531e} EventID 220 Version 0 Level 4 Task 76 Opcode 25 Keywords 0x2000000000000000
    • TimeCreated
    [ SystemTime] 2022-04-10T12:43:35.1046864Z EventRecordID 322 Correlation
    • Execution
    [ ProcessID] 4
    [ ThreadID] 8 Channel Microsoft-Windows-Kernel-Boot/Operational Computer CompName
    • Security
    [ UserID] S-1-5-18
  • EventData TxtStatus 3

Device Guard:
Device Guard successfully processed the Group Policy: Virtualization Based Security = Enabled, Secure Boot = On, DMA Protection = On, Virtualization Based Code Integrity = Enabled, Credential Guard = Enabled, Reboot required = No, Status = 0x0.

Here clearly shows that DMA Protection is on, but when I open msinfo32, here's what I get:

191634-system-guard-msinfo32.png

Any help is greatly appreciated,
Thanks

Windows Hardware Performance
Windows Hardware Performance
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Hardware Performance: Delivering / providing hardware or hardware systems or adjusting / adapting hardware or hardware systems.
1,567 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Namit Sharma 0 Reputation points
    2024-03-05T11:37:18.4466667+00:00

    Hi Romulo I am also having the same issue. There are a few things :- 1 Does your processor support Intel TXT. 2 Does your pc meets all the requirements for system guard (https://www.google.com/url?q=https://learn.microsoft.com/en-us/windows/security/hardware-security/system-guard-secure-launch-and-smm-protection&sa=U&ved=2ahUKEwi_kLGhg92EAxUn2gIHHeRJA6wQFnoECAMQAg&usg=AOvVaw23FMFwwvk21Hzh6zygvPHL) 3 Does your pc has a TPM 2.0 4 It's my Q&A refer to this for more info (https://answers.microsoft.com/en-us/windows/forum/all/firmware-protection-off-and-button-grayed-out/2ddd4c72-c34c-422e-8b3a-92f74794fb1b). If this helps please let me know.

    0 comments No comments