The docs for this feature (available since Dec 2018) seem to be
here. If I'm reading them correctly:
- System Guard = Secure Launch = Firmware protection
- There is a very long list of requirements to enable it (table at the bottom), including Intel vPro 8th gen processor or later (or SD850 or later) and TPM2.
This MSDN blog post, written at Jan 2019, says: "
At the time of this blog post no devices have yet shipped that include hardware support for Secure Launch including all Microsoft Surface devices and any other OEM devices.
The first devices with this support included are not expected to be available on the market until the 2nd quarter of calendar year 2019 "