In the simplest terms, Device Guard is a new Windows 10 optional feature that controls access to boot processes and memory while also blocking any software that is not specifically approved (like a whitelist).
Windows Device Guard is actually a set of three features:
ISSUES WITH DEVICE GUARD:
Very few companies will implement this Device Guard (and its sister Credential Guard) technology because while the tech it self is easy enough to turn on and configure, it is time consuming, inflexible and very difficult to get right. I expect Device Guard to be used in very high security environments with a limited set of infrequently changing applications, like the military (think field hardware) and banks (think ATMs).
For all the details on Device Guard and Credential Guard and how to implement them, see this very nicely written Microsoft article.
This website uses cookies.
View Comments