Uses virtualisation-based security to isolate Kerberos TGTs and NTLM hashes. Windows Server 2025 enables it automatically on domain-joined member servers (not DCs), which breaks live migration relying on CredSSP.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Credential Guard in context, with comparison tables and the common traps.
Terms in this definition
- VBS
Virtualisation-based security walls off a protected area of memory with the Windows hypervisor, keeping secrets and code integrity checks safe. Credential Guard and memory integrity depend on it.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- NTLM
NT LAN Manager, an older Windows challenge-response protocol available through Microsoft Entra Domain Services. Mounting Azure Files over SMB with a key relies on NTLMv2, so permitting Kerberos alone breaks such mounts.
- Live migration
Moving a Hyper-V virtual machine to a different host while it keeps running, without users noticing an outage.
- CredSSP
Hyper-V can use it for live migrations instead of Kerberos constrained delegation; it works by delegating a user's entire credentials to the remote server.
Related terms
- Account protection
Covers Windows LAPS, local user group membership, Credential Guard and Windows Hello for Business in a single Intune endpoint security policy type for Windows. Since July 2024 it has replaced the Identity protection template.
- DES
An outdated encryption type for Kerberos that current versions of Windows disable by default. With Credential Guard turned on, Kerberos cannot use DES at all.
- LSA
Local Security Authority. Running as LSASS, it verifies sign-ins made locally or over the network and applies local security policy; its stored secrets can be shielded with Credential Guard and LSA protection.
- NTLMv1
The first NTLM version. It no longer ships with Windows 11 24H2 or Windows Server 2025, Credential Guard blocks it, and the version a logon relied on is recorded in event 4624.