AMA: The latest in Windows hardware security

Ask Microsoft anything about the latest announcements and innovations in Windows hardware security. If you have questions about new capabilities built on the Microsoft Pluton security processor, advancements in hardware accelerated BitLocker, or other ways Windows technologies work together to reduce attack surfaces, improve device integrity, and deliver faster, more resilient data protection—this is the session for you. Whether you manage fleets or design devices, get the information you need to understand how to take advantage of Windows and hardware advanced security at every layer. https://techcommunity.microsoft.com/e... This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff 0:00 – Welcome & introductions 1:22 – Question – How do I tell—at scale—which devices can support VBS, HVCI, and newer kernel protections? 2:23 – Question – What does VBS actually do at a hardware level? 4:05 – Question – Do all TPMs behave the same, or are there differences between firmware TPM, discrete TPM, and Pluton? 6:22 – Question – How do we verify—remotely—that hardware-based protections are actually running? 8:09 – Question – What exactly does Secure Boot protect against—and what does it/doesn’t it stop? 10:20 – Question – What happens if our devices don't get updated with the new Secure Boot certs in time? • For more info go to https://aka.ms/GetSecureBoot 12:56 – Question – Can VBS or memory integrity break drivers, VPNs, or virtualization tools? 15:30 – Question – Why are features like Credential Guard and HVCI enabled by default on some devices but not others? 17:51 – Question – Will enabling Secure Boot break imaging, recovery media, or dual‑boot scenarios? 19:48 – Question – What’s the real‑world performance impact of VBS on modern CPUs? 20:52 – Question – What happens on older hardware that technically runs Windows 11 but can’t enable all hardware-backed protections? 22:21 – Question – What is kernel mode hardware enforced stack protection, and do we need new CPUs for it? 23:15 – Question – How do we explain the value of hardware-backed security to leadership in plain language?