Forum Discussion

Karl-WE's avatar
Mar 03, 2024
Solved

b26063 - Bug Bash - Windows Security > Device Security - Cannot enable VBS anymore - FIXED

I have updated my UEFI and redeployed Secure Boot settings. now on all windows versions (multiboot) I cannot enable VBS and Core Isolation anymore. I could enable it without errors but it becomes ...
  • Karl-WE's avatar
    Mar 03, 2024

    Ok fixed it. There is a new (BETA) BIOS, released some days ago, which addresses the issue. It is not mentioned in the release notes though.

    I have the strong feeling it is related to the UEFI secure boot changes described in the linked article.

    Believe we could need an urgent advisory. A blogpost isn't enought if this is true.
    If the February changes (not yet fully proven) are able to disable security with unpatched UEFI devices, this would be something very noteable.

    Mind that admins / users don't regularly do BIOS / UEFI updates on Servers or Clients.

     

    Solution in a summary

     

    Hello Lien how are you doing?

    No it has been solved for 22H2.

     

    - update my UEFI from a 2023 to a 2024 beta version from Asrock

    - redeploying Secure Boot keys and make sure it's enabled

    - enabling Core Isolation on the Hyper-V Host (HCVI) which also enables VBS

    - enable vTPM on the Azure Stack HCI nested virtualization VM (mslab)

Resources