Fix errors related to user mode isolation when starting a shielded VM.

Fix user mode isolation errors using Shielded VMs on 2016

John Savill

July 31, 2016

1 Min Read
ITPro Today logo

Q. I receive an error trying to start a Shielded VM that User Mode host isolation is off. How can I fix this?

A. Shielded VMs requires User Mode isolation to help elements of the security. To enable User Mode host isolation the machine must be configured with Secure Boot and the required policy should be set as follows:

  1. Open local or group policy object that applies to the machine

  2. Navigate to Computer Configuration - Administrative Templates - System - Device Guard

  3. Double click Turn on Virtualization Based Security

  4. Set the policy to Enabled

  5. Set the Select Platform Security Level to Secure Boot and the two other options as Disabled (Virtualization Based Protection of Code Integrity and Credential Guard Configuration)

  6. Click OK

About the Author

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like