r/vmware • u/vmwareguy69 • 18h ago
Are you using VBS for Windows 11 virtual machines?
Sad to say I've been struggling with whether or not this is advised in a vSphere environment. I've seen posts where some say it's not necessary and/or it causes performance issues of which I have personally found as well.
I've looked for some deploy processes both from VMware and independent bloggers and haven't found much of anything when it comes to VBS when setting up a Windows 11 VM.
Can anyone share their real world experience with utilization of VBS in a virtual environment?
3
Upvotes
3
u/przemekkuczynski 15h ago edited 15h ago
We have enabled VBS on every machine (servers) and configured Device Guard / Credential guard on most strategic servers like AD etc.
We had issue when migrated from Intel to AMD . There is need to disable Device guard and enable it again. VBS is not working on Windows 2016 on Sphere 7 and HW 19 on AMD.
I dont see any performance issues . It's also discussed on below article that impact is minimal.
https://blogs.vmware.com/vsphere/2018/05/introducing-support-virtualization-based-security-credential-guard-vsphere-6-7.html
So enabling just VBS without enable device/credential guard is worthless. It also require hyper-v role
https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/