Windows下慎用内核隔离
发布时间:2020-12-14 02:29:03 所属栏目:Windows 来源:网络整理
导读:1. 开启内核隔离后只能通过注册表关闭 ? 2. 开启内核隔离后,默认会启动hybrid-v,这个东西和虚拟机是冲突的,这样就用不了虚拟机了. ? 3. 解决方法: 关闭内核隔离后,再关闭已经开启的hybrid-v 基本参考下面,可能要重复几次才能有效的关闭hybrid-v ? Powering o
1. 开启内核隔离后只能通过注册表关闭
?
2. 开启内核隔离后,默认会启动hybrid-v,这个东西和虚拟机是冲突的,这样就用不了虚拟机了.
?
3. 解决方法:
关闭内核隔离后,再关闭已经开启的hybrid-v
基本参考下面,可能要重复几次才能有效的关闭hybrid-v
?
Powering on a vm in VMware Workstation on Windows 10 host where Credential Guard/Device Guard is enabled fails with BSOD (2146361)
Symptoms
Powering on a virtual machine in VMware Workstation prior to version 12.5 on a Windows 10 host where Credential Guard or Device Guard is enabled fails with a blue diagnostic screen (BSOD).
From VMware Workstation 12.5,you see error similar to:
VMware Workstation and Device/Credential Guard are not compatible. VMware Workstation can be run after disabling Device/Credential Guard.
For more information,see Windows 10 host where Credential Guard or Device Guard is enabled fails when running Workstation (2146361)
Purpose
This article provides steps to disable Credential Guard or Device Guard for a Windows 10 Enterprise host.
Cause
This issue occurs because Device Guard or Credential Guard is incompatible with Workstation.
Resolution
To disable Device Guard or Credential Guard:
Disable the group policy setting that was used to enable Credential Guard.
On the host operating system,click Start > Run,type gpedit.msc,and click Ok. The Local group Policy Editor opens.
Go to Local Computer Policy > Computer Configuration > Administrative Templates > System > Device Guard > Turn on Virtualization Based Security.
Select Disabled.
Go to Control Panel > Uninstall a Program > Turn Windows features on or off to turn off Hyper-V.
Select Do not restart.
Delete the related EFI variables by launching a command prompt on the host machine using an Administrator account and run these commands:
mountvol X: /s
copy %WINDIR%System32SecConfig.efi X:EFIMicrosoftBootSecConfig.efi /Y
bcdedit /create {0cb3b571-2f2e-4343-a879-d86a476d7215} /d "DebugTool" /application osloader
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} path "EFIMicrosoftBootSecConfig.efi"
bcdedit /set {bootmgr} bootsequence {0cb3b571-2f2e-4343-a879-d86a476d7215}
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO,DISABLE-VBS
bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} device partition=X:
mountvol X: /d
Note: Ensure X is an unused drive,else change to another drive.
Restart the host.
Accept the prompt on the boot screen to disable Device Guard or Credential Guard.
Related Information
(编辑:李大同) 【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容! |
相关内容
- Windows server 2012 rdp丢弃连接
- windows-phone-7 – CameraCaptureTask仅返回WP7中分辨率为
- 如何在Windows机器上使用R检查系统内存是否可用?
- 如何在Windows Azure上重置VM上的管理员密码?
- windows-server-2003 – 确定谁以管理员权限运行?
- win10无法创建家庭组怎么办 如何加入家庭组
- active-directory – Active Directory域如何加入计算机(本
- Windows MIrror驱动程序远程显示驱动程序VNC服务器窗口8
- Windows Azure Ubuntu – 500 OOPS:在建立FTP连接时出现pr
- windows-server-2008 – 无法还原SQL 2008备份 – 数据库正