Upcoming changes to NTLMv1 in Windows 11, version 24H2 and Windows ...
Credential Guard provides complete protection of both NTLMv1 legacy cryptography and many other attack surfaces, and thus Microsoft strongly recommends its deployment and enablement if Credential Guard’s requirements are met.
Device Security in the Windows Security App - Microsoft Support
Credential Guard helps to protect those tokens by putting them in a protected, virtualized, environment where only certain services can access them when necessary.
April 8, 2025—KB5055523 (OS Build 26100.3775) - Microsoft Support
The feature Machine Accounts in Credential Gurad, which is dependent on password rotation via Kerberos, has also been disabled, until a permanent fix is made available.
How to manage the Windows Boot Manager revocations for Secure Boot ...
This article describes the protection against the publicly disclosed Secure Boot security feature bypass that uses the BlackLotus UEFI bootkit tracked by CVE-2023-24932, how to enable the mitigations, and guidance on bootable media.
April 9, 2024—KB5036896 (OS Build 17763.5696) - EXPIRED
This occurs when you turn on the Remote Credential Guard feature and the client is Windows 11, version 22H2 or higher. This update addresses an issue that affects DNS servers.
Restart failure if Device Guard or Credential Guard isn't disabled ...
A Hyper-V user with BitLocker enabled may encounter a restart failure if the Device Guard or Credential Guard feature has not been disabled or has not been uninstalled cleanly.
Credential Manager in Windows - Microsoft Support
Credential Manager lets you view and delete your saved credentials for signing in to websites, connected applications, and networks. To open Credential Manager, type credential manager in the search box on the taskbar and select Credential Manager Control panel.
Updates to TGT delegation across incoming trusts in Windows Server
If you must enable TGT delegation on a trust, it's recommended that you mitigate that risk by enabling Windows Defender Credential Guard on client computers. This prevents all unconstrained delegation from a computer that has Windows Defender Credential Guard enabled and running.
April 9, 2024—KB5036894 (OS Build 22000.2899) - Microsoft Support
This occurs when you turn on the Remote Credential Guard feature and the client is Windows 11, version 22H2 or higher. This update makes Country and Operator Settings Asset (COSA) profiles up to date for some mobile operators.
Active Directory Domains mitigation plan for vulnerability in TPM
Servicing Windows 10 computers that have the October 2017 security updates will remove the existing TPM credential key. Windows will only provision Credential Guard-protected keys to ensure Pass-the-Ticket protection for domain-joined device keys.