Ithambile

Yenza okanye uvale iNgcaciso yoMkhuseli Windows 10

Zama Isixhobo Sethu Sokuphelisa Iingxaki





Iposwe kwiIgqityelwe ukuvuselelwa: ngoFebruwari 17, 2021

Nika amandla okanye ukhubaze iNgcaciso yoMkhuseli Windows 10: I-Windows Credential Guard isebenzisa ukhuseleko olusekwe kwi-virtualization ukwahlula iimfihlo ukuze kuphela isoftware yenkqubo enelungelo lokufikelela kuzo. Ukufikelela okungagunyaziswanga kwezi mfihlelo kunokukhokelela ekuhlaselweni kobusela obuqinisekisiweyo, njengePass-the-Hash okanye iPass-The-Ticket. I-Windows Credential Guard ikhusela olu hlaselo ngokukhusela i-NTLM password hashes, i-Kerberos Ticket Granting Tickets, kunye neziqinisekiso ezigcinwe zizicelo njengeziqinisekiso zesizinda.



Yenza okanye uvale iNgcaciso yoMkhuseli Windows 10

Ngokuvumela iWindows Credential Guard ezi mpawu zilandelayo kunye nezisombululo zinikezelwe:



Ukhuseleko lwe-Hardware
Ukhuseleko olusekwe kwinyani
Ukhuseleko olungcono kwizoyikiso eziqhubekayo

Ngoku uyakwazi ukubaluleka kweCredential Guard, ngokuqinisekileyo kuya kufuneka wenze le nkqubo yakho. Ke ngaphandle kokuchitha naliphi na ixesha makhe sibone ukuba Unokwenza njani okanye uKhubaze iGcini lokuQinisekisa ngaphakathi Windows 10 ngoncedo lwesifundo esidweliswe ngezantsi.



Imixholo[ fihla ]

Yenza okanye uvale iNgcaciso yoMkhuseli Windows 10

Qiniseka ukuba yenza indawo yokubuyisela nje ukuba kukho into engahambi kakuhle.



Indlela yoku-1: Nika amandla okanye uvale iNgcaciso yoMkhuseli Windows 10 usebenzisa uMhleli wePolisi yeQela

Phawula: Le ndlela isebenza kuphela ukuba uneWindows Pro, Education, okanye Enterprise Edtion. Kubasebenzisi benguqulo yeKhaya leWindows batsiba le ndlela kwaye balandele elandelayo.

1.Cofa iSitshixo seWindows + R uze uchwetheze regedit kwaye ucofe u-Enter ukuze uvule Umhleli woMgaqo-nkqubo weQela.

Qalisa umyalelo regedit

2.Hambela kule ndlela ilandelayo:

Ulungelelwaniso lweKhompyutha > Iitemplates zoLawulo > Inkqubo > IsiGadi seSixhobo

3.Qinisekisa ukuba ukhetha Isixhobo Guard kunakwifestile yasekunene cofa kabini kuyo Layita uKhuseleko oluSekwe kwi-Virtualization umgaqo-nkqubo.

Cofa kabini Vula uMgaqo-nkqubo woKhuseleko osekwe kwiVirtualization

4.Kwi Iimpahla zefestile zomgaqo-nkqubo ongentla qinisekisa ukuba ukhetha Ivuliwe.

Cwangcisa Vula uKhuseleko oluSekwe kwi-Virtualization ukuze uvulelwe

5.Ngoku ukusuka kwi Khetha iNqanaba loKhuseleko lweQonga ukhethe-phantsi Khusela ukuQalisa okanye uKhuseleko lwe-Boot kunye ne-DMA Ukhuseleko.

Ukusuka Khetha iNqanaba loKhuseleko lweNqanaba lokuhla licofe ukuQalisa uKhuseleko okanye uKhuseleko lokuQalisa kunye noKhuseleko lweDMA

6.Okulandelayo, ukusuka Uqwalaselo loMlindi weNgcaciso ukhethe-phantsi Yenziwe nge-UEFI lock . Ukuba ufuna ukucima iCredential Guard ukude, khetha Vuliwe ngaphandle kokutshixa endaweni yeVulwe ngesitshixo se-UEFI.

7.Xa ugqibile, cofa u-Apply ulandelwe ngu-Kulungile.

8.Qalisa kwakhona iPC yakho ukugcina utshintsho.

Indlela yesi-2: Yenza okanye uvale iNgcaciso yoMkhuseli Windows 10 usebenzisa iRegistry Editor

UmGaqo woQinisekiso usebenzisa iimpawu zokhuseleko ezisekwe kwi-virtualization ekufuneka zinikwe amandla kuqala kwinqaku leWindows ngaphambi kokuba wenze okanye ucime iCredential Guard kuRegistry Editor. Qinisekisa ukuba usebenzisa enye kuphela kwezi ndlela zidweliswe ngezantsi ukwenza iimpawu zokhuseleko ezisekwe ngokubonakalayo.

Yongeza iimpawu zokhuseleko ezisekwe ngokubonakalayo ngokusebenzisa iiNkqubo kunye neMiba

1.Cofa iSitshixo seWindows + R uze uchwetheze appwiz.cpl kwaye ucofe u-Enter ukuze uvule Inkqubo kunye neMiba.

chwetheza appwiz.cpl kwaye ucofe u-Enter ukuze uvule iiNkqubo kunye neMiba

2.Ukusuka kwifestile yasekhohlo cofa apha Vula okanye ucime Iimpawu zeWindows .

vula okanye ucime iifitsha zefestile

3.Fumana kwaye wandise I-Hyper-V ngoko ngokufanayo ukwandisa i-Hyper-V Platform.

4.Ngaphantsi kweQonga le-Hyper-V uphawu lokukhangela Hyper-V Hypervisor .

Ngaphantsi kwe-Hyper-V Platform checkmark Hyper-V Hypervisor

5. Ngoku skrolela ezantsi kwaye uphawu lokujonga iNdlela yoMsebenzisi eNyedwa kwaye ucofe u-OK.

Yongeza iimpawu zokhuseleko ezisekwe kumfanekiso ongekho intanethi ngokusebenzisa i-DISM

1.Cofa iSitshixo seWindows + X uze ukhethe I-Command Prompt (Admin).

umyalelo okhawulezayo ngamalungelo olawulo

2.Thayipha lo myalelo ulandelayo kwi-cmd ukongeza i-Hyper-V Hypervisor kwaye ucofe u-Enter:

|_+_|

Yongeza iimpawu zokhuseleko ezisekwe kumfanekiso ongekho intanethi ngokusebenzisa i-DISM

3.Yongeza iNdlela yoMsebenzisi oNyedwa ngokuqhuba lo myalelo ulandelayo:

|_+_|

Yongeza iNdlela yoMsebenzisi oNyedwa

4.Xa ugqibile, ungavala i-prompt yomyalelo.

Yenza okanye uvale iNgcaciso yoMkhuseli Windows 10

1.Cofa iSitshixo seWindows + R uze uchwetheze regedit kwaye ucofe u-Enter ukuze uvule Umhleli woBhaliso.

Qalisa umyalelo regedit

2.Yiya kweli qhosha lilandelayo lobhaliso:

HKEY_LOCAL_MACHINE System CurrentControlSet Control DeviceGuard

3.Cofa ekunene DeviceGuard uze ukhethe Entsha > DWORD (32-bit) Ixabiso.

Cofa ekunene kwi-DeviceGuard emva koko ukhethe i-DWORD entsha (32-bit) ixabiso

4. Xela le DWORD isandula ukuyilwa njenge Yenza iVirtualizationBasedSecurity kwaye ucofe u-Enter.

Xela le DWORD isandula ukuyilwa njenge-EnebleVirtualizationBasedSecurity kwaye ucofe u-Enter

5.Cofa kabini kwi-EnableVirtualizationBasedSecurity DWORD emva koko utshintshe ixabiso layo ukuze:

Ukwenza uKhuseleko olusekwe kwiVirtualization: 1
Ukukhubaza ukhuseleko olusekwe kwi-Virtualization: 0

Ukwenza uKhuseleko olusekwe kwiVirtualization lutshintshe ixabiso le-DWORD ukuya ku-1

6.Ngoku kwakhona cofa ekunene kwi-DeviceGuard emva koko ukhethe Entsha > DWORD (32-bit) Ixabiso kwaye unike igama le DWORD njenge I-RequirePlatformSecurityFeatures emva koko ucofe u-Enter.

Xela le DWORD njengeRequirePlatformSecurityFeatures emva koko ucofe u-Enter

7.cofa kabini kwiRequirePlatformSecurityFeatures DWORD kunye tshintsha ixabiso ukuya ku-1 ukusebenzisa i-Security Boot kuphela okanye yibeke ku-3 ukusebenzisa uKhuseleko lwe-Boot kunye nokhuseleko lwe-DMA.

Yitshintshe

8.Ngoku yiya kweli qhosha lilandelayo lobhaliso:

HKEY_LOCAL_MACHINE System CurrentControlSet Control LSA

9.Cofa ekunene kwi-LSA uze ukhethe Entsha > DWORD (32-bit) Ixabiso uze unike igama le DWORD njenge Iiflegi zeLsaCfg kwaye ucofe u-Enter.

Cofa ekunene kwi-LSA uze ukhethe Entsha emva koko DWORD (32-bit) Ixabiso

10.Cofa kabini kwi-LsaCfgFlags DWORD kwaye utshintshe ixabiso layo ngoku:

Khubaza uMgcini weNgcaciso: 0
Nika amandla uMgcini woBugcisa ngesitshixo se-UEFI: 1
Yenza uMgcini weNgqinisekiso ngaphandle kokutshixa: 2

Cofa kabini kwi LsaCfgFlags DWORD kwaye utshintshe ixabiso layo ngokwe

11.Xa kugqityiwe, vala uMhleli weRegistry.

Khubaza isiQinisekiso sokuGcinwa ngaphakathi Windows 10

Ukuba iCredential Guard yenziwe ngaphandle kwe-UEFI Tshixo ngoko unako Khubaza i-Windows Credential Guard usebenzisa i Isixhobo sokuGada kunye neCredential Guard isixhobo sokulungela izixhobo okanye le ndlela ilandelayo:

1.Cofa iSitshixo seWindows + R uze uchwetheze regedit kwaye ucofe u-Enter ukuze uvule Umhleli woBhaliso.

Qalisa umyalelo regedit

2.Khangela kwaye ucime la maqhosha alandelayo obhaliso:

|_+_|

Khubaza i-Windows Credential Guard

3. Cima Windows Credential Guard EFI variables ngokusebenzisa bcdedit . Cofa i-Windows Key + X uze ukhethe I-Command Prompt (Admin).

umyalelo okhawulezayo ngamalungelo olawulo

4.Thayipha lo myalelo ulandelayo kwi-cmd kwaye ucofe u-Enter:

|_+_|

5.Xa ugqibile, vala i-prompt yomyalelo kwaye uqalise kwakhona iPC yakho.

6.Yamkela uncedo lokuvala iWindows Credential Guard.

eCetyisiweyo: