Credential Guard Setup
System Requirements for Credential Guard¶
- CPU Support:
- Must support Second Level Address Translation (SLAT), which is available on modern Intel (VT-d) and AMD (AMD-Vi) processors.
-
Ensure the CPU supports Virtualization-Based Security (VBS), a prerequisite for Credential Guard.
-
Operating System:
- Windows 10 version 1607 or later.
-
Windows Server 2016 or later (including Windows Server 1809, which is part of the Server 2016 lifecycle).
-
Hyper-V:
- Hyper-V must be enabled and configured to support virtualization-based security.
-
The system must be running on a hypervisor that supports virtualization (e.g., Hyper-V).
-
Secure Boot:
-
Secure Boot must be enabled in the BIOS/UEFI settings to ensure the system boots in a trusted state.
-
Optional TPM Support:
- While not strictly required, a Trusted Platform Module (TPM) 1.2 or later can enhance security for Credential Guard configurations involving BitLocker.
Enabling Credential Guard via Group Policy¶
-
Configure Virtualization-Based Security:
Enable the policy "Enable virtualization-based security" and "Enable Credential Guard".
Open the Group Policy Management Console (GPMC) and edit the relevant GPO. Navigate to:
-
Set Hyper-V Configuration:
Set this to Enabled to ensure Hyper-V is activated.
In the same GPO, locate "Enable Hyper-V" under:
-
Apply and Reboot:
- Deploy the GPO to the target computers.
- Reboot the system to apply changes.
Enabling Hyper-V and Virtualization-Based Security¶
-
Enable Hyper-V via PowerShell:
Reboot the system after execution.
Run the following command to ensure Hyper-V is enabled:
-
Verify Hyper-V Status:
Check if Hyper-V is enabled using:
-
Confirm SLAT Support:
If SLAT is supported, the command will return processor details indicating SLAT capability.
Use the following command to verify SLAT is supported:
Verification and Troubleshooting¶
-
Check Credential Guard Status:
If Credential Guard is enabled, the output will reflect virtualization-based security settings.
Run the following command to verify Credential Guard is active:
-
Troubleshoot Common Issues:
- "Hyper-V is not available": Ensure the system meets the hardware requirements and Secure Boot is enabled.
- "Credential Guard failed to start": Check the event logs for errors (e.g., Event ID 41) and ensure all prerequisites are met.
Key takeaways¶
- Credential Guard requires SLAT-enabled CPUs, Windows 10/Server 2016+, and Hyper-V.
- Enable Hyper-V via PowerShell and configure GPO settings to activate Credential Guard.
- Verify system compliance using PowerShell commands and ensure Secure Boot is enabled.
- Troubleshoot by checking event logs and confirming all hardware/software prerequisites are met.