Event banner
AMA: Windows 11 upgrade paths and deployment tools
Event details
Welcome to the Windows 11 upgrade paths and deployment tools Ask Microsoft Anything (AMA)! This live hour gives you the opportunity to ask questions and provide feedback to the engineering and product teams building Windows. Introduce yourself by replying to this thread. Post each question in the Comment on this event… box above.
- Kasper JensenAug 26, 2021Brass Contributor
The line is drawn because Gen 8/Zen 2 (technically Gen 7 too) are the first processors to support http://borec.ch/the-potential-performance-impact-of-device-guard-hvci/, a hardware feature to speed up HVCI, a security feature used for kernel driver validation and for some enterprise security features such as WDAG/Device Guard and force-enabled on Windows 11.
Without MBEC on the processor, HVCI is much slower and somewhat cripples the CPU, therefore the "experience" argument from Microsoft.
Opinion: Microsoft have been shady about this from the very start, with no official explanation and false arguments (no, Secure Boot, VBS and HVCI enabled but unconfigured will not stop https://www.microsoft.com/security/blog/2021/01/11/new-surface-pcs-enable-virtualization-based-security-vbs-by-default-to-empower-customers-to-do-more-securely/).
I think HVCI in isolation is useless for consumers and small businesses alike as malicious kernel drivers or Mimikatz usage is not going to be the primary focus for attackers when the user is local admin already.
- DaseinAug 27, 2021Copper ContributorAlso wasn't Windows 10 meant to be the last version of Windows? Did something change there? 🤔
- Kasper JensenAug 27, 2021Brass Contributor
That was always an urban legend - one engineer overspoke to a journalist and it blew up from there.
We've always known that Windows 10 would only be supported for 10 years, https://web.archive.org/web/20150728070925/http://windows.microsoft.com/en-us/windows/lifecycle at the RTM release of Windows 10 1507 showing the 2025 support end date.