LsaCfgFlags

Use to enable the Credential Guard, which uses virtualization-based security to isolate secrets so that only privileged system software can access them when they are stored on disk or in memory. For more information, see Credential Guard.

Values

Value Description

0

Disables Credential Guard.

This is the default OS value.

1

Enables Credential Guard.

2

Enables Credential Guard without making it persist to the UEFI.

Parent Hierarchy

Microsoft-Windows-DeviceGuard-Unattend | LsaCfgFlags

Valid Configuration Passes

offlineServicing

Applies To

Windows 10 Enterprise

Windows Server 2016

For a list of the Windows editions and architectures that this component supports, see Microsoft-Windows-DeviceGuard-Unattend.