1.118 WN10-CC-000070

Information

Virtualization Based Security must be enabled on Windows 10 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.

GROUP ID: V-220811RULE ID: SV-220811r1016359

Virtualization Based Security (VBS) provides the platform for the additional security features, Credential Guard and Virtualization based protection of code integrity. Secure Boot is the minimum security level with DMA protection providing additional memory protection. DMA Protection requires a CPU that supports input/output memory management unit (IOMMU).

Solution

VBS, including Credential Guard, currently cannot be implemented in virtual desktop implementations (VDI) due to specific supporting requirements including a TPM, UEFI with Secure Boot, and the capability to run the Hyper-V feature within the virtual desktop.

For VDIs where the virtual desktop instance is deleted or refreshed upon logoff, this is NA.

Configure the policy value for

Computer Configuration >> Administrative Templates >> System >> Device Guard >> 'Turn On Virtualization Based Security'

to 'Enabled' with 'Secure Boot' or 'Secure Boot and DMA Protection' selected for 'Select Platform Security Level:'.

A Microsoft article on Credential Guard system requirements can be found at the following link: https://technet.microsoft.com/en-us/itpro/windows/keep-secure/credential-guard-requirements

See Also

https://workbench.cisecurity.org/benchmarks/23869

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(13)

Plugin: Windows

Control ID: 28af59ca405f9ddcdc74c2f3b306a420159660d2a7b2514946047c16bf18fdd4