Skip to content

Credential Guard Setup

System Requirements for Credential Guard

  1. CPU Support:
  2. Must support Second Level Address Translation (SLAT), which is available on modern Intel (VT-d) and AMD (AMD-Vi) processors.
  3. Ensure the CPU supports Virtualization-Based Security (VBS), a prerequisite for Credential Guard.

  4. Operating System:

  5. Windows 10 version 1607 or later.
  6. Windows Server 2016 or later (including Windows Server 1809, which is part of the Server 2016 lifecycle).

  7. Hyper-V:

  8. Hyper-V must be enabled and configured to support virtualization-based security.
  9. The system must be running on a hypervisor that supports virtualization (e.g., Hyper-V).

  10. Secure Boot:

  11. Secure Boot must be enabled in the BIOS/UEFI settings to ensure the system boots in a trusted state.

  12. Optional TPM Support:

  13. While not strictly required, a Trusted Platform Module (TPM) 1.2 or later can enhance security for Credential Guard configurations involving BitLocker.

Enabling Credential Guard via Group Policy

  1. Configure Virtualization-Based Security:
    Open the Group Policy Management Console (GPMC) and edit the relevant GPO. Navigate to:

    Computer Configuration > Administrative Templates > System > Credential Guard
    
    Enable the policy "Enable virtualization-based security" and "Enable Credential Guard".

  2. Set Hyper-V Configuration:
    In the same GPO, locate "Enable Hyper-V" under:

    Computer Configuration > Administrative Templates > System > Group Policy
    
    Set this to Enabled to ensure Hyper-V is activated.

  3. Apply and Reboot:

  4. Deploy the GPO to the target computers.
  5. Reboot the system to apply changes.

Enabling Hyper-V and Virtualization-Based Security

  1. Enable Hyper-V via PowerShell:
    Run the following command to ensure Hyper-V is enabled:

    Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All
    
    Reboot the system after execution.

  2. Verify Hyper-V Status:
    Check if Hyper-V is enabled using:

    Get-WindowsOptionalFeature -Online | Where-Object { $_.FeatureName -eq "Microsoft-Hyper-V" }
    

  3. Confirm SLAT Support:
    Use the following command to verify SLAT is supported:

    Get-WmiObject -Class Win32_Processor | Where-Object { $_.AddressWidth -ge 40 }
    
    If SLAT is supported, the command will return processor details indicating SLAT capability.


Verification and Troubleshooting

  1. Check Credential Guard Status:
    Run the following command to verify Credential Guard is active:

    Get-CimInstance -ClassName Win32_ComputerSystem | Select-Object -ExpandProperty VirtualizationBasedSecurity
    
    If Credential Guard is enabled, the output will reflect virtualization-based security settings.

  2. Troubleshoot Common Issues:

  3. "Hyper-V is not available": Ensure the system meets the hardware requirements and Secure Boot is enabled.
  4. "Credential Guard failed to start": Check the event logs for errors (e.g., Event ID 41) and ensure all prerequisites are met.

Key takeaways

  • Credential Guard requires SLAT-enabled CPUs, Windows 10/Server 2016+, and Hyper-V.
  • Enable Hyper-V via PowerShell and configure GPO settings to activate Credential Guard.
  • Verify system compliance using PowerShell commands and ensure Secure Boot is enabled.
  • Troubleshoot by checking event logs and confirming all hardware/software prerequisites are met.