Credential Guard Policies
Windows Server's Credential Guard is a critical security feature that isolates credentials in a secure, virtualized environment to protect against credential theft. Configuring Credential Guard via Group Policy Objects (GPOs) ensures consistent enforcement across managed systems. This section outlines the steps to configure Credential Guard policies using GPOs and verify their effectiveness with PowerShell cmdlets.
Prerequisites for Credential Guard¶
Before configuring Credential Guard, ensure the following:
- Hyper-V and virtualization are enabled: Verify via bcdedit /enum or the System Properties UI.
- Windows 10/11 or Windows Server 2016/2019/2022: Credential Guard requires modern Windows versions.
- TPM 2.0 or Secure Boot: For virtualization-based security (VBS) to function.
Configuring Credential Guard Policies via GPO¶
- Open Group Policy Management Console (GPMC) and create/edit a GPO.
- Navigate to:
Computer Configuration > Administrative Templates > System > Credential Guard - Configure the following policies:
1. Enable Credential Guard¶
- Policy: Enable Credential Guard
- Action: Set to Enabled.
- Purpose: Activates Credential Guard on the system.
2. Configure Isolation Mode¶
- Policy: Configure the Credential Guard isolation mode
- Options:
- Hyper-V: Uses Hyper-V virtualization (requires Hyper-V enabled).
- Microsoft Antimalware Service Executable: Uses the Microsoft Defender service for isolation.
- Recommendation: Use Hyper-V for stronger isolation.
3. Enable Virtualization-Based Security (VBS)¶
- Policy: Turn on Virtualization-Based Security
- Action: Set to Enabled.
- Purpose: Enables the underlying hardware-based security features required for Credential Guard.
Verifying Credential Guard Configuration¶
Use PowerShell cmdlets to confirm the configuration and status:
1. Check Credential Guard Status¶
- Output: Displays whether Credential Guard is enabled, the isolation mode, and virtualization settings.2. Verify Isolation Mode¶
- Output: Shows the current isolation mode (e.g.,Hyper-V or MicrosoftAntimalware).
3. Check Virtualization-Based Security (VBS) Status¶
- Output: Indicates if VBS is enabled and the associated security features (e.g., Secure Kernel Isolation).4. Review Event Logs¶
- Event ID 41: Indicates Credential Guard is running.
- Event ID 10001: May signal issues with virtualization or VBS configuration.
Key takeaways¶
- GPO policies like Enable Credential Guard and Turn on Virtualization-Based Security are essential for enforcing Credential Guard.
- Isolation mode selection (Hyper-V vs. Microsoft Antimalware) impacts security and compatibility.
- PowerShell cmdlets (
Get-CredentialGuardStatus,Get-VBSStatus) provide real-time verification of configuration and operational status. - Always ensure Hyper-V, VBS, and TPM 2.0 are enabled before applying policies.