No there is no other option, you need to reset Windows to put it back inti its initial state without all the changes you have already made.
Firmware protection off and button grayed out
I enabled firmware protection via Group Policy editor, but when I went to windows security the firmware protection button was off and grayed out with a message "This setting is managed by your administrator."
I want the fix and turn on Firmware protection
Windows for home | Windows 11 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
53 answers
Sort by: Oldest
-
Anonymous
2024-02-10T23:48:13+00:00 I can fully confirm the problem. It's a bug. Somehow Firmware protection also disappears when you change the values from Enabled 1 and Managed 1 to anything else. I also used the Device Guard and Credential Guard hardware readiness tool. I have the latest pricey system on the market. I also enabled IOMMU Hyper-V etc. so the full security potencial but nothing works. Is there somehow a way to activate "Turn On Virtualization Based Security + Secure Launch" without triggering the Group Policy? Manually registering in the Registry doesn't work either.
-
Anonymous
2024-02-11T13:52:55+00:00 The issues I found
The Event Viewer says: System Guard enabled but not supported. Reason: The required platform module was not found.
But I have the latest fTPM 2.0 module on my AMD Ryzen 5950XAlso in services you can't run System Guard Runtime Monitor Broker.
-
Anonymous
2024-02-11T15:24:13+00:00 Yes its a bug after making managed dword to 0 or deleting it hides firmware protection from windows security
Thanks for your reply!
Pls can you tell where did you find system guard event in event viewer please tell
-
Anonymous
2024-02-11T15:54:23+00:00 I found the issue. Only dTPM 2.0 is supported.
The determined way: Your MB has an integrated dTPM 2.0 that you can use.
For AMD Users: You need to buy a TPM SPI 2.0 Module, plug it in the SPI_TPM Port and switch it in the BIOS to SPI TPM.
For Intel Users: You can luckily enable Intel PTT 2.0 and Intel TXT and it should work.For branded PC/Laptop: Look if it has a Microsoft Pluton processor.