Workstation crashes with BSOD SECURE_KERNEL_ERROR

Samuel Parker 60 Reputation points
2026-09-25T14:04:51.21+00:00

Workstation crashes with BSOD SECURE_KERNEL_ERROR upon boot after Group Policy enabled Credential Guard on legacy hardware lacking Virtualization-Based Security (VBS) support. How do we disable VBS via UEFI variables?

Windows for business | Windows Client for IT Pros | Devices and deployment | Other
0 comments No comments

Answer accepted by question author
Xuan Nhu 1,370 Reputation points Independent Advisor
2026-09-25T14:44:46.1233333+00:00

Hello Samual, sorry to hear about the crash!

To recover the system, boot into a WinPE environment or recovery drive to access the command line and disable Virtualization-Based Security at the boot level.

First, run bcdedit /set hypervisorlaunchtype off and bcdedit /set vsmlaunchtype off to prevent the Windows bootloader from initializing VBS on unsupported hardware.

Next, clear the persistent Credential Guard EFI variables by running reg load HKLM\OFFLINE C:\Windows\System32\config\SYSTEM and deleting the key HKLM\OFFLINE\ControlSet001\Control\DeviceGuard\Scenarios\CredentialGuard. If the NVRAM variables persist at the firmware level, use the UEFI Shell command dmpstore -d -guid 77004374-4276-4ea0-a151-6f0820f147d1 to purge all Guard-related flags.

Once the machine reboots successfully into Windows, temporarily move its computer object into an Active Directory OU with Group Policy inheritance blocked so the policy does not immediately re-apply.

Hope the guideline is helpful to you. Let me know how it works after applying it, and if you find my response helpful to you, please give it a thumps-up, I would really appreciate it :)

XN.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.