# Device Guard `Computer Configuration\Administrative Templates\System\Device Guard` - Turn On Virtualization Based Security -> Enabled (**Only do this if you are running Windows on bare metal or with nested virtualization**)