Site icon WinCert

Windows 11 22H2 is even more secure on Intel 12th Gen PCs

<p>Since the release of Windows 11&comma; Microsoft has pointed out that security is a crucial aspect of its latest OS&period; To explain the importance of features of TMP 2&period;0 and Core Isolation the company even demoed hacking attacks on mock systems&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4830" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2022&sol;11&sol;cpu-g4fa4da31d&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"427" &sol;><&sol;p>&NewLine;<p>In a blog post by Microsoft&&num;8217&semi;s Jin Lin&comma; a PM Manager at Azure and Windows OS platform&comma; the company has confirmed new development and said that TME-MK is available on Intel&&num;8217&semi;s 3rd Gen Xeon scalable Ice Lake and also on 12th Gen Alder Lake processors&period; A list of supported guest operating systems can be found <a href&equals;"https&colon;&sol;&sol;learn&period;microsoft&period;com&sol;en-us&sol;azure&sol;virtual-machines&sol;generation-2&num;generation-2-vm-images-in-azure-marketplace" target&equals;"&lowbar;blank" rel&equals;"noopener">here<&sol;a>&period;<&sol;p>&NewLine;<p>Below you may find the procedure on how to enable multi-key total memory encryption&colon;<&sol;p>&NewLine;<p>To boot a new Virtual Machine with TME-MK protection which assigns it a unique encryption key from other partitions we should use Powershell&period;<&sol;p>&NewLine;<p>Open Powershell in elevated mode &lpar;run as admin&rpar;<&sol;p>&NewLine;<p>type the following command&colon;<&sol;p>&NewLine;<p><em><strong>Set-VMMemory -VMName -MemoryEncryptionPolicy EnabledIfSupported<&sol;strong><&sol;em><&sol;p>&NewLine;<p>In order to verify if a VM has enabled TME-MK for memory encryption the following command can be used&colon;<&sol;p>&NewLine;<p><em><strong>Get-VmMemory -VmName &vert; fl &ast;<&sol;strong><&sol;em><&sol;p>&NewLine;<p>The output result should be like this&colon;<&sol;p>&NewLine;<p><em><strong>MemoryEncryptionPolicy &colon; EnabledIfSupported<br &sol;>&NewLine;<&sol;strong><strong>MemoryEncryptionEnabled &colon; True<&sol;strong><&sol;em><&sol;p>&NewLine;

Exit mobile version