赞
踩
您好,
了解到您的问题,请您先不要着急。
在专业版当中
如下是vmware官方帮助文档,您可以根据以下两篇文章来解决该问题
https://kb.vmware.com/s/article/2146361
https://blog.csdn.net/qq_23599965/article/detai...
_______________________________________________
免责声明:以上涉及到的网址链接均[不是]来自微软的官方网站。这些页面所提供的信息均较为准确可靠不过依然提醒您需要注意这些页面可能会包含您有可能不需要的产品广告,所以在您下载安装这些广告产品的时候请务必看清楚并确认这是您所需要的。
希望这可以帮助到您。
我根据提示去微软网站上下载了【dgreadiness_v3.6】软件,运行后依旧无法关闭【基于虚拟化的安全】服务,软件报错如下:
###########################################################################
Readiness Tool Version 3.4 Release.
Tool to check if your device is capable to run Device Guard and Credential Guard.
###########################################################################
Disabling Device Guard and Credential Guard
Deleting RegKeys to disable DG/CG
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "EnableVirtualizationBasedSecurity" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "RequirePlatformSecurityFeatures" /f
Output:
Major Minor Build Revision
----- ----- ----- --------
10 0 18362 0
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "Locked" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "HypervisorEnforcedCodeIntegrity" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v "LsaCfgFlags" /f
Output:
Executing: del "$env:windir\System32\CodeIntegrity\SIPolicy.p7b"
Output:
Disabling Hyper-V and IOMMU
Major Minor Build Revision
----- ----- ----- --------
10 0 18362 0
部署映像服务和管理工具
版本: 10.0.18362.1
映像版本: 10.0.18362.239
错误: 0x800f080c
功能名称 Microsoft-Hyper-V-Online 未知。
未识别出 Windows 功能名称。
请使用 /Get-Features 选项在映像中查找功能名称,然后重试该命令。
可以在 C:\WINDOWS\Logs\DISM\dism.log 上找到 DISM 日志文件
Disabling Hyper-V failed please check the log file
FreeDrive=X:
Executing: mountvol $FreeDrive /s
Output:
Executing: bcdedit /create "{0cb3b571-2f2e-4343-a879-d86a476d7215}" /d DGOptOut /application osloader
Exception while exectuing bcdedit /create "{0cb3b571-2f2e-4343-a879-d86a476d7215}" /d DGOptOut /application osloader
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" path \EFI\Microsoft\Boot\SecConfig.efi
Exception while exectuing bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" path \EFI\Microsoft\Boot\SecConfig.efi
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{bootmgr}" bootsequence "{0cb3b571-2f2e-4343-a879-d86a476d7215}"
Exception while exectuing bcdedit /set "{bootmgr}" bootsequence "{0cb3b571-2f2e-4343-a879-d86a476d7215}"
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" loadoptions DISABLE-LSA-ISO,DISABLE-VBS
Exception while exectuing bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" loadoptions DISABLE-LSA-ISO,DISABLE-VBS
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" device partition=$FreeDrive
Exception while exectuing bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" device partition=$FreeDrive
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: mountvol $FreeDrive /d
Output:
PC will restart in 30 seconds
Executing: shutdown /r /t 30
Output:
###########################################################################
Readiness Tool Version 3.4 Release.
Tool to check if your device is capable to run Device Guard and Credential Guard.
###########################################################################
Disabling Device Guard and Credential Guard
Deleting RegKeys to disable DG/CG
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "EnableVirtualizationBasedSecurity" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "RequirePlatformSecurityFeatures" /f
Output:
Major Minor Build Revision
----- ----- ----- --------
10 0 18362 0
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "Locked" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v "HypervisorEnforcedCodeIntegrity" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /f
Output:
Executing: REG DELETE "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v "LsaCfgFlags" /f
Output:
Executing: del "$env:windir\System32\CodeIntegrity\SIPolicy.p7b"
Output:
Disabling Hyper-V and IOMMU
Major Minor Build Revision
----- ----- ----- --------
10 0 18362 0
部署映像服务和管理工具
版本: 10.0.18362.1
映像版本: 10.0.18362.239
错误: 0x800f080c
功能名称 Microsoft-Hyper-V-Online 未知。
未识别出 Windows 功能名称。
请使用 /Get-Features 选项在映像中查找功能名称,然后重试该命令。
可以在 C:\WINDOWS\Logs\DISM\dism.log 上找到 DISM 日志文件
Disabling Hyper-V failed please check the log file
FreeDrive=W:
Executing: mountvol $FreeDrive /s
Output:
Executing: bcdedit /create "{0cb3b571-2f2e-4343-a879-d86a476d7215}" /d DGOptOut /application osloader
Exception while exectuing bcdedit /create "{0cb3b571-2f2e-4343-a879-d86a476d7215}" /d DGOptOut /application osloader
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" path \EFI\Microsoft\Boot\SecConfig.efi
Exception while exectuing bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" path \EFI\Microsoft\Boot\SecConfig.efi
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{bootmgr}" bootsequence "{0cb3b571-2f2e-4343-a879-d86a476d7215}"
Exception while exectuing bcdedit /set "{bootmgr}" bootsequence "{0cb3b571-2f2e-4343-a879-d86a476d7215}"
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" loadoptions DISABLE-LSA-ISO,DISABLE-VBS
Exception while exectuing bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" loadoptions DISABLE-LSA-ISO,DISABLE-VBS
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" device partition=$FreeDrive
Exception while exectuing bcdedit /set "{0cb3b571-2f2e-4343-a879-d86a476d7215}" device partition=$FreeDrive
无法将“bcdedit”项识别为 cmdlet、函数、脚本文件或可运行程序的名称。请检查名称的拼写,如果包括路径,请确保路径正确,然后再试一次。
Executing: mountvol $FreeDrive /d
Output:
PC will restart in 30 seconds
Executing: shutdown /r /t 30
Output:
###########################################################################
Readiness Tool Version 3.4 Release.
Tool to check if your device is capable to run Device Guard and Credential Guard.
###########################################################################
How to read the output:
1. Red Errors: Basic things are missing that will prevent enabling and using DG/CG
2. Yellow Warnings: This device can be used to enable and use DG/CG, but additional security benefits will be absent. To learn more please go through: https://aka.ms/dgwhcr
3. Green Messages: This device is fully compliant with DG/CG requirements
###########################################################################
Hardware requirements for enabling Device Guard and Credential Guard
1. Hardware: Recent hardware that supports virtualization extension with SLAT
###########################################################################
Usage: DG_Readiness.ps1 -[Capable/Ready/Enable/Disable/Clear] -[DG/CG/HVCI] -[AutoReboot] -Path
Log file with details is found here: C:\DGLogs
To Enable DG/CG. If you have a custom SIPolicy.p7b then use the -Path parameter else the hardcoded default policy is used
Usage: DG_Readiness.ps1 -Enable OR DG_Readiness.ps1 -Enable -Path
To Enable only HVCI
Usage: DG_Readiness.ps1 -Enable -HVCI
To Enable only CG
Usage: DG_Readiness.ps1 -Enable -CG
To Verify if DG/CG is enabled
Usage: DG_Readiness.ps1 -Ready
To Disable DG/CG.
Usage: DG_Readiness.ps1 -Disable
To Verify if DG/CG is disabled
Usage: DG_Readiness.ps1 -Ready
To Verify if this device is DG/CG Capable
Usage: DG_Readiness.ps1 -Capable
To Verify if this device is HVCI Capable
Usage: DG_Readiness.ps1 -Capable -HVCI
To Auto reboot with each option
Usage: DG_Readiness.ps1 -[Capable/Enable/Disable] -AutoReboot
###########################################################################
Readiness Tool with '-capable' is run the following RegKey values are set:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Capabilities
CG_Capable
DG_Capable
HVCI_Capable
Value 0 = not possible to enable DG/CG/HVCI on this device
Value 1 = not fully compatible but has sufficient firmware/hardware/software features to enable DG/CG/HVCI
Value 2 = fully compatible for DG/CG/HVCI
###########################################################################
Not an Admin user, pls execute this script as an Admin user exiting...
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。