Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Windows 11 no longer has a single feature or switch called Device Guard. Microsoft now treats Device Guard as the name used for related Group Policy and registry locations. The protections people usually mean are Virtualization-based Security (VBS), Memory integrity—also called Hypervisor-protected Code Integrity (HVCI)—and Credential Guard.

For most PCs, start by turning off Memory integrity in Windows Security. If VBS or Credential Guard is also active, disable those separately. A restart is required after changing these protections.

Before disabling Device Guard protections

These security features protect Windows kernel code and credentials from malicious or vulnerable software. Turning them off can allow an incompatible driver or application to run, but it reduces protection against kernel-level attacks and credential theft.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If this is a work or school computer, check with your administrator first. A Group Policy, Intune policy, or UEFI lock may turn the setting back on or prevent local changes from working.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Also create a restore point or make sure you have a current backup before changing security configuration. If you are disabling the feature because of a driver problem, first look for a newer driver from the hardware or software manufacturer.

Method 1: Turn off Memory integrity in Windows Security

This disables HVCI, the component most commonly associated with the old “Device Guard” terminology.

  1. Open Windows Security from the Start menu.
  2. Select Device security.
  3. Under Core isolation, select Core isolation details.
  4. Turn Memory integrity off.
  5. Restart Windows when prompted.

Beginning with Windows 11 version 22H2, Windows Security displays a warning when Memory integrity is off. You may also see the warning on the Windows Security taskbar icon and in Notification Center. That warning is expected; it does not mean the setting failed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Method 2: Disable HVCI from an elevated terminal

Use this method when the Memory integrity switch is unavailable or the graphical setting does not change.

  1. Open Start and search for Command Prompt or PowerShell.
  2. Select Run as administrator.
  3. Run this command:
reg add "HKLMSYSTEMCurrentControlSetControlDeviceGuardScenariosHypervisorEnforcedCodeIntegrity" /v "Enabled" /t REG_DWORD /d 0 /f
  1. Restart the computer.

This changes the HVCI setting only. It does not automatically disable Credential Guard or every other VBS service.

Method 3: Disable VBS with Local Group Policy

Windows 11 Pro, Enterprise, and Education editions may include the Local Group Policy Editor. The setting is not available in Windows Home unless you use centrally managed policy through another method.

  1. Press Windows+R, type gpedit.msc, and press Enter.
  2. Go to Computer Configuration → Administrative Templates → System → Device Guard.
  3. Double-click Turn on Virtualization Based Security.
  4. Select Disabled, then select OK.
  5. Restart Windows.

On a domain-joined computer, an administrator can apply updated policy with:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
gpupdate /force

A restart is still required before the VBS or Credential Guard state change takes effect.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Disable Credential Guard separately

Credential Guard is a separate VBS component. Turning off Memory integrity does not necessarily turn off Credential Guard. It is available on Windows Enterprise and Education editions, and Microsoft has enabled it by default on supported devices beginning with Windows 11 version 22H2.

Using Group Policy

  1. Open gpedit.msc as an administrator.
  2. Go to Computer Configuration → Administrative Templates → System → Device Guard.
  3. Open Turn On Virtualization Based Security.
  4. Choose Disabled, then select OK.
  5. Restart the computer.

This works when Credential Guard was enabled without a UEFI lock and is not being enforced by another policy.

Using Microsoft Intune

For an Intune-managed device, create or edit a Settings catalog policy:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open the Device Guard category.
  2. Set Credential Guard to Disabled.
  3. Assign the policy to the device or user.
  4. Allow the policy to sync, then restart Windows.

The custom-policy equivalent is:

Item Value
Setting Credential Guard Configuration
OMA-URI ./Device/Vendor/MSFT/Policy/Config/DeviceGuard/LsaCfgFlags
Data type int
Value 0

Using the registry

Use the registry only when Credential Guard is not protected by a UEFI lock and no Group Policy or MDM policy is enforcing it. Open an elevated Command Prompt and run:

reg add "HKLMSYSTEMCurrentControlSetControlLsa" /v "LsaCfgFlags" /t REG_DWORD /d 0 /f
reg add "HKLMSOFTWAREPoliciesMicrosoftWindowsDeviceGuard" /v "LsaCfgFlags" /t REG_DWORD /d 0 /f

Restart afterward. Microsoft specifically documents setting these values to 0; deleting LsaCfgFlags may not disable Credential Guard.

What to do if UEFI lock is enabled

A UEFI lock stores the security configuration in firmware. Windows Security, Group Policy, and ordinary registry edits cannot remove that configuration by themselves. Disabling a UEFI-locked feature requires physical presence at the computer to confirm a pre-boot prompt.

For Credential Guard, Microsoft provides the following procedure from an elevated Command Prompt:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
mountvol X: /s
copy %WINDIR%System32SecConfig.efi X:EFIMicrosoftBootSecConfig.efi /Y
bcdedit /create {0cb3b571-2f2e-4343-a879-d86a476d7215} /d "DebugTool" /application osloader
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} path "EFIMicrosoftBootSecConfig.efi"
bcdedit /set {bootmgr} bootsequence {0cb3b571-2f2e-4343-a879-d86a476d7215}
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} device partition=X:
mountvol X: /d

Restart the PC. Before Windows starts, confirm the UEFI-change prompt. If you do not confirm it, the change will not persist.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Do not use this procedure casually: bcdedit changes the boot configuration, and a mistake can make the system difficult to start. On a managed computer, involve the IT administrator.

If UEFI-locked Memory integrity prevents normal boot

If enabling Memory integrity with UEFI lock causes instability or a boot failure, Microsoft documents a Windows Recovery Environment procedure. Disable the policies that enabled VBS or HVCI, boot into Windows RE, and run:

reg add "HKLMSYSTEMCurrentControlSetControlDeviceGuardScenariosHypervisorEnforcedCodeIntegrity" /v "Enabled" /t REG_DWORD /d 0 /f

Microsoft notes that Secure Boot must be disabled to complete this Windows RE procedure when UEFI lock is involved. Re-enable Secure Boot afterward if your recovery process permits it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check whether the protections are actually disabled

Do not rely only on the Windows Security interface. Open PowerShell as administrator and run:

Get-CimInstance -ClassName Win32_DeviceGuard -Namespace rootMicrosoftWindowsDeviceGuard

Important output values are:

Property Value Meaning
SecurityServicesConfigured 1 Credential Guard is configured
SecurityServicesConfigured 2 Memory integrity is configured
SecurityServicesRunning 1 Credential Guard is running
SecurityServicesRunning 2 Memory integrity is running
VirtualizationBasedSecurityStatus 0 VBS is not enabled
VirtualizationBasedSecurityStatus 1 VBS is enabled but not running
VirtualizationBasedSecurityStatus 2 VBS is enabled and running

To check Credential Guard specifically, run:

(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace rootMicrosoftWindowsDeviceGuard).SecurityServicesRunning

An output of 0 means Credential Guard is not running; 1 means it is running. Microsoft does not recommend using the LsaIso.exe process in Task Manager as the verification method.

You can also open msinfo32.exe, select System Summary, and check Virtualization-based Security and Virtualization-based Security Services Running.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the setting may come back after restarting

If Memory integrity or Credential Guard returns after a reboot, check these causes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Group Policy: A local or domain policy may be enforcing VBS.
  • Intune or another MDM: The device may receive the setting again during its next sync.
  • UEFI lock: The configuration may be stored in firmware and require a pre-boot confirmation to remove.
  • Default Credential Guard enablement: Supported Windows 11 version 22H2 or later devices may enable Credential Guard by default unless an explicit disabled policy is present.

Registry edits do not override these enforcement mechanisms. Check the policy source before repeatedly changing the same registry value.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Driver problems caused by Memory integrity

Memory integrity can block an incompatible kernel driver. The result may be a device that stops working, software that fails to start, or—rarely—a boot failure or blue screen.

First, update the driver through Device Manager or download a Windows 11-compatible version from the hardware manufacturer. If no compatible driver exists and you need the device or application immediately, disable Memory integrity using one of the methods above, restart, and test again. Re-enable it after replacing the incompatible software.

On Azure virtual machines, VBS can also show as enabled but not running. Microsoft documents an edge case where selecting Secure Boot with DMA causes this state because Azure VMs do not support Memory integrity with that selection. In that situation, changing local registry settings may not solve the underlying configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Is Device Guard still a Windows 11 setting?

No. Microsoft says Device Guard is no longer used as the name of a current Windows Security feature, apart from related Group Policy and registry locations. The modern features are VBS, Memory integrity/HVCI, and Credential Guard.

Does turning off Memory integrity disable Credential Guard?

Not necessarily. Memory integrity and Credential Guard are separate VBS components. Check Credential Guard with the Win32_DeviceGuard PowerShell command and disable it separately if it is running.

Why can’t I turn off Memory integrity?

A Group Policy, Intune/MDM policy, or UEFI lock may be enforcing the setting. An incompatible driver can also prevent Windows from applying the change normally. Check policy management and verify the state after a restart.

Will disabling Device Guard make Windows unsafe?

It reduces protection for kernel code and, if Credential Guard is also disabled, reduces protection for Windows credentials. Disable only the specific component needed for compatibility, then update the affected driver or application and re-enable the protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does VBS status 1 mean?

A value of 1 for VirtualizationBasedSecurityStatus means VBS is enabled or configured but is not currently running. A value of 0 means it is not enabled, while 2 means it is enabled and running.

The Bottom Line

For a typical Windows 11 PC, use Windows Security → Device security → Core isolation details and turn off Memory integrity, then restart. If Credential Guard or VBS remains active, disable it through the appropriate Group Policy, Intune policy, or registry setting. If the protection was enabled with a UEFI lock, ordinary Windows changes are insufficient: the device needs the Microsoft pre-boot removal procedure and physical confirmation. Verify the result with Win32_DeviceGuard or msinfo32.exe rather than assuming the first switch disabled everything.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.