On paper, Credential Guard should increase security on network- or corporation-managed devices. However, if you happen to have Windows 11 Enterprise or Education and are using it for personal use, you might find it limiting virtualization software options. Here’s how to disable Credential Guard (Windows 11 version).
How to Check if Credential Guard Is Active
In most cases, Windows 11 devices running on the Enterprise or Education edition will have the feature running by default. Microsoft has force-enabled it on applicable devices back with version 22H2, and you should’ve been prompted to update past it.
You can check if the feature is active through the System Information utility.
Step 1. In the Run utility, open “msinfo32.”

Step 2. In the System Summary, look for the entries under “Virtualization-based security,” such as “Virtualization-based security Services Configured” and “Virtualization-based security Services Running.”

Step 3. If Credential Guard is configured, it should appear under “Virtualization-based security Services Configured.”
If Credential Guard doesn’t appear and you have Windows 11 Enterprise or Education, the feature may not be enabled, or the device may not meet its hardware and software requirements.
Part 1 – Disable Credential Guard (Windows 11) via Group Policy for non-UEFI Lock
The Group Policy option should be the easiest and can even be used to apply the change to multiple managed computers. This only applies if the UEFI lock wasn’t enabled when turning on Credential Guard for the first time (or if the setting was turned on in BIOS before).
Step 1. Open the Run utility and run “gpedit.msc”
Step 2. Go to the following address:
Computer Configuration\Administrative Templates\System\Device Guard
Step 3. Open the “Device Guard” folder and the “Turn on Virtualization-Based Security Policy” setting.
Step 4. Select “Disabled” and click “Apply” and “OK.”
Step 5. Exit the utility and restart the PC.
If Credential Guard was enabled without UEFI lock and isn’t being controlled by Group Policy, you can disable it through the registry.
Step 1. Open the Registry Editor.
Step 2. Go to the following registry key and set the LsaCfgFlags value to 0:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Step 3. Set the flag to 0.
Step 4. Go to the following registry key and set the LsaCfgFlags value to 0:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard
Step 5. Set that value to 0 as well.
Step 6. Exit the Registry Editor and restart the PC.
If Group Policy is controlling Credential Guard, registry changes may be overridden by the policy. Microsoft recommends setting these registry values to 0 instead of deleting them.

Part 2 – Disabling Credential Guard With UEFI Lock
If the UEFI lock was enabled, you’ll need to follow the first option, and then remove the lock as well through Command Prompt. This requires physical presence at the PC because you must confirm the change at boot using a function key.
Step 1. Open the Command Prompt with administrator access.
Step 2. Run the following commands one by one:
mountvol X: /s
copy %WINDIR%\System32\SecConfig.efi X:\EFI\Microsoft\Boot\SecConfig.efi /Y
bcdedit /create {0cb3b571-2f2e-4343-a879-d86a476d7215} /d “DebugTool” /application osloader
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} path “\EFI\Microsoft\Boot\SecConfig.efi”
bcdedit /set {bootmgr} bootsequence {0cb3b571-2f2e-4343-a879-d86a476d7215}
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} device partition=X:
mountvol X: /d
Step 3. Restart the PC. Before Windows starts, a prompt will appear to notify you that UEFI was modified and ask you to confirm the change. Follow the on-screen instructions and press the required function key to confirm.
Was this helpful?
Last updated on 28 September, 2026
The article above may contain affiliate links which help support Guiding Tech. The content remains unbiased and authentic and will never affect our editorial integrity.


