Forum Discussion

HasanHasib's avatar
HasanHasib
Copper Contributor
Dec 31, 2024

Turn on Memory Integrity through Microsoft Intune

Hi,

Question: How to turn on the following setting through Microsoft Intune?
 
Windows Security > Device Security > Core isolation > Memory Integrity
(It says: Memory integrity is off. Your device may be vulnerable.)
 
Applied licenses: Microsoft Intune Suite + Microsoft Defender for Endpoint P2
Client OS: Windows 11
 
It has been weeks since I already applied the following through the Security Baseline Policy for Windows 10 and Later but still the Memory Integrity has not got enabled on any client:
 
Device Guard
Credential Guard: (Enabled with UEFI lock): Turns on Credential Guard with UEFI lock.
Enable Virtualization Based Security: enable virtualization based security.
Require Platform Security Features: Turns on VBS with Secure Boot and direct memory access (DMA).
------
Virtualization Based Technology
Hypervisor Enforced Code Integrity: (Enabled with UEFI lock) Turns on Hypervisor-Protected Code Integrity with UEFI lock.
 
The Windows Baseline Security has got applied successfully on all endpoints without any errors or conflicts. Intune Sync and device restart have been performed 100s of times but in vain.
 
Any suggestions would be highly appreciated.

No RepliesBe the first to reply

Resources