This CSP contains some settings that are under development and only applicable for Windows Insider Preview builds. These settings are subject to change and may have dependencies on other features or services in preview.
ConfigureSystemGuardLaunch
Scope
Editions
Applicable OS
✅ Device ❌ User
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC
Credential Guard Configuration: 0 - Turns off CredentialGuard remotely if configured previously without UEFI Lock, 1 - Turns on CredentialGuard with UEFI lock. 2 - Turns on CredentialGuard without UEFI lock.
Description framework properties:
Property name
Property value
Format
int
Access Type
Add, Delete, Get, Replace
Default Value
0
Allowed values:
Value
Description
0 (Default)
(Disabled) Turns off Credential Guard remotely if configured previously without UEFI Lock.
1
(Enabled with UEFI lock) Turns on Credential Guard with UEFI lock.
2
(Enabled without lock) Turns on Credential Guard without UEFI lock.
Group policy mapping:
Name
Value
Name
VirtualizationBasedSecurity
Friendly Name
Turn On Virtualization Based Security
Element Name
Credential Guard Configuration.
Location
Computer Configuration
Path
System > Device Guard
Registry Key Name
SOFTWARE\Policies\Microsoft\Windows\DeviceGuard
ADMX File Name
DeviceGuard.admx
MachineIdentityIsolation
Scope
Editions
Applicable OS
✅ Device ❌ User
❌ Pro ✅ Enterprise ✅ Education ❌ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC
Machine Identity Isolation: 0 - Machine password is only LSASS-bound and stored in $MACHINE.ACC registry key. 1 - Machine password both LSASS-bound and IUM-bound. It's stored in $MACHINE.ACC and $MACHINE.ACC.IUM registry keys. 2 - Machine password is only IUM-bound and stored in $MACHINE.ACC.IUM registry key.
Description framework properties:
Property name
Property value
Format
int
Access Type
Add, Delete, Get, Replace
Default Value
0
Allowed values:
Value
Description
0 (Default)
(Disabled) Machine password is only LSASS-bound and stored in $MACHINE.ACC registry key.
1
(Enabled in audit mode) Machine password both LSASS-bound and IUM-bound. It's stored in $MACHINE.ACC and $MACHINE.ACC.IUM registry keys.
2
(Enabled in enforcement mode) Machine password is only IUM-bound and stored in $MACHINE.ACC.IUM registry key.
Group policy mapping:
Name
Value
Name
VirtualizationBasedSecurity
Friendly Name
Turn On Virtualization Based Security
Element Name
Machine Identity Isolation Configuration.
Location
Computer Configuration
Path
System > Device Guard
Registry Key Name
SOFTWARE\Policies\Microsoft\Windows\DeviceGuard
ADMX File Name
DeviceGuard.admx
RequirePlatformSecurityFeatures
Scope
Editions
Applicable OS
✅ Device ❌ User
❌ Pro ✅ Enterprise ✅ Education ❌ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC
Illustrare i concetti fondamentali della protezione dei dati, della gestione del ciclo di vita, della protezione delle informazioni e della conformità per proteggere una distribuzione di Microsoft 365.