Firmware protection off and button grayed out

Anonymous
2024-01-07T04:08:09+00:00

I enabled firmware protection via Group Policy editor, but when I went to windows security the firmware protection button was off and grayed out with a message "This setting is managed by your administrator."

I want the fix and turn on Firmware protection

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

53 answers

Sort by: Most helpful
  1. Anonymous
    2024-02-11T15:54:23+00:00

    I found the issue. Only dTPM 2.0 is supported.
    The determined way: Your MB has an integrated dTPM 2.0 that you can use.
    For AMD Users: You need to buy a TPM SPI 2.0 Module, plug it in the SPI_TPM Port and switch it in the BIOS to SPI TPM.
    For Intel Users: You can luckily enable Intel PTT 2.0 and Intel TXT and it should work.

    For branded PC/Laptop: Look if it has a Microsoft Pluton processor.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-02-11T15:24:13+00:00

    Yes its a bug after making managed dword to 0 or deleting it hides firmware protection from windows security

    Thanks for your reply!

    Pls can you tell where did you find system guard event in event viewer please tell

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-02-11T13:52:55+00:00

    The issues I found

    The Event Viewer says: System Guard enabled but not supported. Reason: The required platform module was not found.
    But I have the latest fTPM 2.0 module on my AMD Ryzen 5950X

    Also in services you can't run System Guard Runtime Monitor Broker.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-02-10T23:48:13+00:00

    I can fully confirm the problem. It's a bug. Somehow Firmware protection also disappears when you change the values from Enabled 1 and Managed 1 to anything else. I also used the Device Guard and Credential Guard hardware readiness tool. I have the latest pricey system on the market. I also enabled IOMMU Hyper-V etc. so the full security potencial but nothing works. Is there somehow a way to activate "Turn On Virtualization Based Security + Secure Launch" without triggering the Group Policy? Manually registering in the Registry doesn't work either.

    Was this answer helpful?

    0 comments No comments
  5. DaveM121 933.9K Reputation points Independent Advisor
    2024-01-08T15:26:09+00:00

    No there is no other option, you need to reset Windows to put it back inti its initial state without all the changes you have already made.

    Was this answer helpful?

    0 comments No comments