Virtualization Based Security cannot be disabled in 23H2


Local time
2:34 PM
Posts
2
OS
Windows 11 23H2
Hello. I'm on build 22631. Win11 just updated to 23H2. In the process, a key app for me ceased working, due to VBS being enabled. It worked under Win11 22H2, with the Memory Integrity setting disabled. (Long story short: I undervolt and achieve a 77% overclock on my i7-8750h, cannot upgrade to a newer laptop due to reasons. ThrottleStop ceased working, Intel XTU doesn't work either and blames VBS. I do a very CPU-demanding work for a living and this is the only PC I'll have access to in the short to medium term.)

I've tried the following:
  1. Core Isolation / Memory Integrity is off. (It "stayed" off between 22H2 and 23H2)
  2. Disabled Credential Guard

    Following this guide Configure Credential Guard - Windows Security, I disabled Credential Guard both with the Group Policy Editor and with the registry,

    I also disabled Credential Guard with UEFI lock, which asked me to press F3 before loading Windows twice, once for Credential Guard and then for VBS

  3. Disabled VBS with the bcdedit commands as instructed here (the Group Policy option is the same as in the Credential Guard subsection!)

  4. I've turned off Virtual Machine Platform (VMP) using these instructions Options to optimize gaming performance in Windows 11 - Microsoft Support

  5. I see no relevant BIOS options (other than outright disabling all virtualization)
Despite all of these steps and rebooting countless times, VBS is still enabled. This is what msinfo32 shows:

1715964262697.png

I'm out of ideas. Any help would be greatly appreciated. I use this PC for working on CPU-heavy apps, and truly halving the performance of an already old processor is killing me.
 
Windows Build/Version
22631

My Computer

System One

  • OS
    Windows 11 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1E Gen 1
    CPU
    i7-8750h
    Memory
    32GB PC2666
    Graphics Card(s)
    1050ti
    Sound Card
    Creative Sound Blaster 16

My Computers

System One System Two

  • OS
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF Gaming F16 (2024)
    CPU
    i7 13650HX
    Memory
    16GB DDR5
    Graphics Card(s)
    GeForce RTX 4060 Mobile
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    512GB SSD internal
    37TB external
    PSU
    Li-ion
    Cooling
    2× Arc Flow Fans, 4× exhaust vents, 5× heatpipes
    Keyboard
    Logitech K800
    Mouse
    Logitech G402
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
  • Operating System
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Medion S15450
    CPU
    i5 1135G7
    Memory
    16GB DDR4
    Graphics card(s)
    Intel Iris Xe
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    2TB SSD internal
    37TB external
    PSU
    Li-ion
    Mouse
    Logitech G402
    Keyboard
    Logitech K800
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF

My Computer

System One

  • OS
    Windows 11 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1E Gen 1
    CPU
    i7-8750h
    Memory
    32GB PC2666
    Graphics Card(s)
    1050ti
    Sound Card
    Creative Sound Blaster 16

My Computer

System One

  • OS
    Windows 11
Do you run a 3rd party AV?
 

My Computers

System One System Two

  • OS
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF Gaming F16 (2024)
    CPU
    i7 13650HX
    Memory
    16GB DDR5
    Graphics Card(s)
    GeForce RTX 4060 Mobile
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    512GB SSD internal
    37TB external
    PSU
    Li-ion
    Cooling
    2× Arc Flow Fans, 4× exhaust vents, 5× heatpipes
    Keyboard
    Logitech K800
    Mouse
    Logitech G402
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
  • Operating System
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Medion S15450
    CPU
    i5 1135G7
    Memory
    16GB DDR4
    Graphics card(s)
    Intel Iris Xe
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    2TB SSD internal
    37TB external
    PSU
    Li-ion
    Mouse
    Logitech G402
    Keyboard
    Logitech K800
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
I did ALL of them except the InTune solution, as I describe in the first post.
From what I can read, you didn't describe that in your 1st post at all. The link I gave says to also turn off 2 more Windows features (i.e., Microsoft Defender Application Guard and Windows Hypervisor Platform) in addition to turning off VMP.
 

My Computers

System One System Two

  • OS
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF Gaming F16 (2024)
    CPU
    i7 13650HX
    Memory
    16GB DDR5
    Graphics Card(s)
    GeForce RTX 4060 Mobile
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    512GB SSD internal
    37TB external
    PSU
    Li-ion
    Cooling
    2× Arc Flow Fans, 4× exhaust vents, 5× heatpipes
    Keyboard
    Logitech K800
    Mouse
    Logitech G402
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
  • Operating System
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Medion S15450
    CPU
    i5 1135G7
    Memory
    16GB DDR4
    Graphics card(s)
    Intel Iris Xe
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    2TB SSD internal
    37TB external
    PSU
    Li-ion
    Mouse
    Logitech G402
    Keyboard
    Logitech K800
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
What version of Windows are you on? Home, Pro, Enterprise, etc?

I had this same issue on 2 different computers running Win11 Education (which is basically just Enterprise edition rebranded). After you disable everything regarding VBS and Credential Guard in group policy, reboot, then come back in and in an elevated shell run this command.

bcdedit /set hypervisorlaunchtype off

After rebooting it should be off.
 

My Computer

System One

  • OS
    Windows 11
Hi,

I was used different options and the only thing that work for me was DG Readiness Tool.

Thanks @Bizarre
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    lenovo
I am on latest build of 23h2 right now (got latest update tonight) and I am using throttlestop right now and it's working with no problem!
The only thing I have disabled is Core isolation and even have vmware workstation running! So I think that the problem is not from windows 23h2! Are you sure you didn't get a bios update? New bios updates are blocking undervolting and on my laptop also the latest bios disables undervolting. So I have to stick with an older version to keep this working.

Screenshot 2024-08-14 030144.png
screenshot-2024-08-14-030905-png.104761
Screenshot 2024-08-14 030241.png
 

Attachments

  • Screenshot 2024-08-14 030905.png
    Screenshot 2024-08-14 030905.png
    9.4 KB · Views: 14

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo Legion 7i
    CPU
    Intel i7-12800HX
    Memory
    32 GB DDR5 4800 MHz dual-channel
    Graphics Card(s)
    NVIDIA® GeForce RTX™ 3080 Ti
    Sound Card
    Steinberg UR44
    Hard Drives
    1 TB SSD (M.2 NVMe PCIe 4.0 x4
    2 TB SSD Samsung 980 PRO NNMe
    Browser
    Firefox
    Antivirus
    Windows Defender + Malwarebytes
I am on latest build of 23h2 right now (got latest update tonight) and I am using throttlestop right now and it's working with no problem!
The only thing I have disabled is Core isolation and even have vmware workstation running! So I think that the problem is not from windows 23h2! Are you sure you didn't get a bios update? New bios updates are blocking undervolting and on my laptop also the latest bios disables undervolting. So I have to stick with an older version to keep this working.
Your laptop's CPU does not let you undervolt it. The older BIOS just gives you the fake impression that it does, but it still doesn't. See this reddit post from unclewebb, the author of ThrottleStop:
 

My Computers

System One System Two

  • OS
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF Gaming F16 (2024)
    CPU
    i7 13650HX
    Memory
    16GB DDR5
    Graphics Card(s)
    GeForce RTX 4060 Mobile
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    512GB SSD internal
    37TB external
    PSU
    Li-ion
    Cooling
    2× Arc Flow Fans, 4× exhaust vents, 5× heatpipes
    Keyboard
    Logitech K800
    Mouse
    Logitech G402
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
  • Operating System
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Medion S15450
    CPU
    i5 1135G7
    Memory
    16GB DDR4
    Graphics card(s)
    Intel Iris Xe
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    2TB SSD internal
    37TB external
    PSU
    Li-ion
    Mouse
    Logitech G402
    Keyboard
    Logitech K800
    Internet Speed
    20Mbit/s up, 250Mbit/s down
    Browser
    FF
Hello hdmi :)
I am sorry for the confusion I created because of not updating my PC info. My CPU is a 12800HX. But for those with CPU's that do not undervolt , ThrottleStop should not show that the offset is applied. It will show the offset as 0. One should also check with other monitoring software.
Screenshot 2024-08-14 151518.pngScreenshot 2024-08-14 154516.png
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo Legion 7i
    CPU
    Intel i7-12800HX
    Memory
    32 GB DDR5 4800 MHz dual-channel
    Graphics Card(s)
    NVIDIA® GeForce RTX™ 3080 Ti
    Sound Card
    Steinberg UR44
    Hard Drives
    1 TB SSD (M.2 NVMe PCIe 4.0 x4
    2 TB SSD Samsung 980 PRO NNMe
    Browser
    Firefox
    Antivirus
    Windows Defender + Malwarebytes

Latest Support Threads

Latest Tutorials

Back
Top Bottom