To enable Device Guard on your Windows 10 computer using Local Group Policy Editor, complete the following steps:
- Press the Windows key + R to open Run.
- Enter gpedit.msc and press Enter.
- In the Local Group Policy Editor window, expand Computer Configuration | Administrative Templates | System | Device Guard and then, on the details pane, double-click Turn On Virtualization based Security (see Figure 14.6):
- In the Turn On Virtualization based Security window, check the Enabled option.
- In the Options section, select the Secure Boot option for Select Platform Security Level ...