Error applying VBS and HVCI security baselines via endpoint/intune

Ben Johnston 0 Reputation points
2025-01-08T15:09:54.77+00:00

Receiving the following errors when attempting to apply the security baselines to some machines via intuneUser's image

I can see both services are already running on the machine (which rules out hardware support, configuration etc)

Screenshot 2025-01-07 192725.png

I can see this error (amongst a few others) in event viewer

MDM PolicyManager: Policy is rejected by licensing, Policy: (EnableVirtualizationBasedSecurity), Area: (DeviceGuard), Result:(0x82B00006) Unknown Win32 Error code: 0x82b00006.

Which implies a licensing problem, however it's Windows 11 Business so should have support

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,967 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 50,866 Reputation points Microsoft Vendor
    2025-01-09T01:39:52.46+00:00

    @Ben Johnston, Thanks for posting in Q&A. Based on my researching, for the two settings, they support on Pro, Enterprise, Education and IoT Enterprise / IoT Enterprise LTSC edition. For Windows 11 Business, it is not supported. Therefore, we will get licensing error. Please upgrade to the supported edition to fix the issue.

    User's image

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#enablevirtualizationbasedsecurity

    User's image

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-virtualizationbasedtechnology#hypervisorenforcedcodeintegrity

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.