You have an Active Directory domain and all domain-joined devices run Microsoft Defender Credential Guard with UEFI lock enabled. You deploy a Windows Server named Server1 and disable Credential Guard on that server. To ensure Server1 is not subject to Credential Guard restrictions, what should you do next?
Choose an answer
Tap an option to check your answer.
Correct answer: Disable the "Turn on Virtualization Based Security" Group Policy setting..
Why this is the answer
The correct answer is to disable the "Turn on Virtualization Based Security" Group Policy setting. Credential Guard relies on Virtualization-Based Security (VBS) to protect credentials. Even if Credential Guard is disabled locally, if the VBS Group Policy is enabled, it can re-enable Credential Guard or enforce other VBS features, thus imposing restrictions. Disabling this Group Policy ensures VBS, and consequently Credential Guard, remains off. Running DISM with /Disable-Feature and /FeatureName:IsolatedUserMode is incorrect because this command disables the Isolated User Mode feature, which is a component of VBS, but it doesn't guarantee that Credential Guard won't be re-enabled by Group Policy or that other VBS protections won't be enforced. The Device Guard and Credential Guard hardware readiness tool is used to check compatibility, not to disable features.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed