Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
Hey Kongo,Hey guys,
been sitting here for hours figuring out how to enable that bs. Every other feature is enabled but I cant seem to get this one working.
Can anybody help please? I am really desperate right now.
Thank you in advance!
View attachment 293016
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard
Tried that already sir.Hey Kongo,
I can see why you're frustrated, it's definitely annoying when a setting is greyed out like that.
The message "Diese Einstellung wird vom Administrator verwaltet" means "This setting is managed by your administrator". This usually happens when a setting is controlled by a Group Policy or a registry entry, rather than directly in the Windows Security app. This can sometimes be set by other security software or system utilities.
First off, is this your personal computer or is it a device from your work or school? If it's a work/school device, you'll likely need to contact your IT department as they have probably configured this policy intentionally.
If this is your personal PC, you can try checking the Group Policy Editor. Please note that this is not available on Windows Home editions.
- Press the Windows Key + R, type gpedit.msc, and press Enter.
- Navigate to: Computer Configuration > Administrative Templates > System > Device Guard
- Look for a policy named "Turn On Virtualization Based Security".
- If its status is "Enabled" or "Disabled", double-click it and change the setting to "Not Configured".
- Click OK and restart your computer.
If you have a Home edition of Windows, or if the above doesn't work, the change might be in the registry.
Warning: Editing the registry can be risky if you're not careful. Please consider creating a backup of the registry before making any changes.
- Press the Windows Key + R, type regedit, and press Enter.
- Navigate to the following key:
Code:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard- In the right-hand pane, look for a value called "EnableVirtualizationBasedSecurity".
- If this value is present and set to 0, it's likely what is disabling the Firmware Protection. You can try deleting this value.
- Restart your computer for the changes to take effect.
Hope this helps you get it sorted out. Let us know how it goes
Hey Kongo,Tried that already sir.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\SystemGuard
Thanks, but I already have that enabled. Doesn't change anything.@Kongo
Try checking the value of this registry key:
Code:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\SystemGuard
Of course, you must open regedit as an Administrator.
P.S.
My wife is German (born in Koblenz) but she's out shopping right now, and I read/speak very little of your language.
So I may have misunderstood your screen.
Thanks, but I already have that enabled. Doesn't change anything.![]()
The settings to enable/disable it should be there in the BIOS. I successfully disabled Secure Boot and virtualization-based security in the BIOS.Thanks, but I already have that enabled. Doesn't change anything.![]()
I did but now the setting doesn't even appear in Security Center. It only appears when I enforce all DeviceGuard settings via Group Policy but then it's greyed out and disabled as shown in the screenshot... Is it hardware related? Maybe my hardware doesn't support it?Enabled to 1?
You need to disable it to 0 and the message “managed...” should disappear.
Then you can change the switch to enable the feature.
Try it out.
It's not a BIOS related setting as far as I know.The settings to enable/disable it should be there in the BIOS. I successfully disabled Secure Boot and virtualization-based security in the BIOS.
I suggested looking into the BIOS, as, according to @Bot, the firmware protection and virtualization-based security are the same. I have virtualization-based security, i.e., "Intel Virtualization" in the BIOS, but I don't see firmware protection there or in Windows Security. Are firmware protection and virtualization-based security the same?It's not a BIOS related setting as far as I know.![]()
Hi rashmi,I suggested looking into the BIOS, as, according to @Bot, the firmware protection and virtualization-based security are the same. I have virtualization-based security, i.e., "Intel Virtualization" in the BIOS, but I don't see firmware protection there or in Windows Security. Are firmware protection and virtualization-based security the same?
According to Windows Security, my system doesn't meet "Standard Security" requirements. Our kids' systems meet "Advanced Security" requirements. I'll see if their systems have firmware protection in the BIOS and in Windows Security when they visit me and update here.
I disabled Secure Boot and Intel Virtualization Technology/VT-x in the BIOS. Does disabling Secure Boot and Intel Virtualization remove the firmware protection feature from Windows Security?Make sure TPM, Secure Boot, and virtualization are all actually enabled in firmware.
Yes – disabling Secure Boot and Intel Virtualization Technology (VT‑x) will effectively remove the conditions Windows needs to offer “firmware protection” as shown in Windows Security.I disabled Secure Boot and Intel Virtualization Technology/VT-x in the BIOS. Does disabling Secure Boot and Intel Virtualization remove the firmware protection feature from Windows Security?
I did but now the setting doesn't even appear in Security Center. It only appears when I enforce all DeviceGuard settings via Group Policy but then it's greyed out and disabled as shown in the screenshot... Is it hardware related? Maybe my hardware doesn't support it?
Members who viewed this thread in the last 5 minutes