Virtualisation-based security walls off a protected area of memory with the Windows hypervisor, keeping secrets and code integrity checks safe. Credential Guard and memory integrity depend on it.
Also called virtualisation-based security.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains VBS in context, with comparison tables and the common traps.
Terms in this definition
- Hypervisor
The virtualisation software allowing many isolated virtual machines to run on a single physical server. The cloud provider looks after it whichever service type is used.
- Integrity
One leg of the CIA triad: information remains correct and is only changed through approved means. Hashes, digital signatures and audit trails help guard it.
- Credential Guard
Uses virtualisation-based security to isolate Kerberos TGTs and NTLM hashes. Windows Server 2025 enables it automatically on domain-joined member servers (not DCs), which breaks live migration relying on CredSSP.
Related terms
- Intel SGX
Intel's hardware-based secure enclave technology. Always Encrypted relies on it for DC-series hardware in Azure SQL Database until it goes out of support at the end of October 2027 (31 October), after which VBS enclaves take over.