You manage an OU named Tier0 that contains Windows Server 2022 domain controllers running on physical hardware. All machines currently boot in legacy BIOS mode. Your security team requires Windows Defender Credential Guard to be enabled and locked so local administrators cannot disable it. You will deploy the change using Group Policy. What two actions must you perform to meet the requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Reconfigure the servers to boot with UEFI and Secure Boot and ensure hardware virtualization with SLAT is enabled in firmware., Enable “Turn On Virtualization Based Security” in a GPO with Credential Guard Configuration set to “Enabled with UEFI lock” and Platform Security Level set to “Secure Boot.”.
Why this is the answer
Credential Guard requires specific hardware and software configurations. First, the servers must boot in UEFI mode with Secure Boot enabled, and hardware virtualization (with Second Level Address Translation, SLAT) must be active in the firmware. Legacy BIOS does not support the necessary security features. Second, a Group Policy Object (GPO) must be configured to enable "Virtualization Based Security" with "Credential Guard Configuration" set to "Enabled with UEFI lock" and "Platform Security Level" set to "Secure Boot." The "UEFI lock" ensures local administrators cannot disable it. LSA protection (RunAsPPL) is a related but separate security measure and doesn't directly enable Credential Guard. The Hyper-V role is not required for Credential Guard on a host, as Credential Guard uses Hyper-V technology but doesn't need the full role installed. The policy "Allow delegating saved credentials with NTLM-only server authentication" is unrelated to Credential Guard's functionality.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed