Enabling Virtualization‑Based Security with HVCI on Windows 11: Decision Guide
A concise decision guide for enabling VBS/HVCI on Windows 11: hardware prerequisites, option table, trade‑offs, step‑by‑step implementation, validation, and rollback.
13 Oct 2025, 01:54 UTC

Decision: Enable or Disable VBS/HVCI
Before turning on Virtualization‑Based Security (VBS) with Hypervisor‑protected Code Integrity (HVCI) in Windows 11, you must weigh security gains against possible performance impacts and driver compatibility issues. This guide outlines the decision constraints, compares the supported configuration options, explains the trade‑offs, and provides a concrete implementation and validation path.
Constraints and Prerequisites
- CPU with virtualization extensions (Intel VT‑x or AMD‑V) and Second Level Address Translation (SLAT).
- TPM 2.0 enabled in firmware.
- Secure Boot enabled.
- Administrative rights to modify Group Policy or the registry.
Supported Options
| Option | Description | Typical Use Case |
|---|---|---|
| Disabled (default on some editions) | VBS and HVCI are not active. | Devices where maximum compatibility or raw I/O performance is required. |
| Core isolation with Memory integrity off | VBS components are loaded but HVCI enforcement is disabled. | Testing environments or systems needing VBS features (e.g., Credential Guard) without full HVCI. |
| Core isolation with Memory integrity on | Full VBS/HVCI enforcement (recommended for security‑hardened deployments). | Enterprise devices where kernel‑level exploit mitigation is a priority. |
Trade‑offs
Enabling Memory integrity (full VBS/HVCI) provides:
- Increased resistance to kernel‑level code injection and exploit techniques.
- Protection for Credential Guard and other VBS‑dependent features.
Potential downsides include:
- Measurable CPU overhead in I/O‑heavy workloads (storage, networking).
- Boot failure if any driver is unsigned, test‑signed, or not HVCI‑compatible.
- Incompatibility with certain kernel‑mode anti‑cheat, debugging, or legacy software.
Concrete Implementation
You can enable the feature via Group Policy or PowerShell. Both methods require a reboot to take effect.
Using Group Policy
- Open the Group Policy Editor (
gpedit.msc). - Navigate to Computer Configuration → Administrative Templates → System → Device Guard.
- Double‑click Turn on Virtualization Based Security.
- Set to Enabled.
- Under Platform Security Level, choose Secure Boot and DMA protection (or Secure Boot, DMA protection, and HVCI for full enforcement).
- Click OK, close the editor, and reboot.
Using PowerShell (run as Administrator)
# Enable VBS and HVCI enforcement
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity' -Name 'Enabled' -Value 1 -Type DWord
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity' -Name 'RequireSecuritySettings' -Value 1 -Type DWord
# Ensure the Virtual Machine Platform feature is present (required for the hypervisor)
Enable-WindowsOptionalFeature -Online -FeatureName VirtualMachinePlatform -NoRestart
Enable-WindowsOptionalFeature -Online -FeatureName PlatformHypervisor -NoRestart
# Reboot to apply changes
shutdown /r /t 0
Validation Steps
After the system restarts, verify that VBS/HVCI is active:
- Open System Information (
msinfo32). In the System Summary section, confirm that Virtualization‑based security reads Running. - Run PowerShell to check the hypervisor presence:
Get-WindowsOptionalFeature -Online -FeatureName VirtualMachinePlatform,PlatformHypervisor | Format-List FeatureName, State - Confirm Credential Guard status:
Get-CimInstance -Namespace root\Microsoft\Windows\DeviceGuard -ClassName Win32_DeviceGuard -Property SecureBootEnabled,VirtualizationBasedSecurityStatus - Optionally, use the built‑in deviceguard tool:
deviceguard /status
Limitations and Practical Checks
Even after successful enablement, some scenarios may still cause issues:
- Driver signing: Any kernel‑mode driver that is not WHQL‑signed or is test‑signed will prevent boot. Use
sigverifto scan for unsigned drivers before enabling. - Performance impact: Run a representative workload (e.g., file copy benchmark) before and after enabling to measure delta. Tools like
DiskSpdcan help. - Application compatibility: Test critical line‑of‑business applications in a pilot group. Look for events in
Event Viewer → Microsoft-Windows-CodeIntegrity/Operationalthat indicate HVCI violations.
Rollback (Disabling VBS/HVCI)
If you need to revert the change, simply reverse the policy or registry settings and reboot:
Via Group Policy
- Set Turn on Virtualization Based Security to Not Configured or Disabled.
- Reboot.
Via PowerShell
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity' -Name 'Enabled' -Value 0 -Type DWord
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity' -Name 'RequireSecuritySettings' -Value 0 -Type DWord
shutdown /r /t 0
After reboot, repeat the validation steps to confirm that Virtualization‑based security now shows Not running.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.