Device Security in Windows 11/10

The ‘Device Security‘ protection area in Windows 11/10, is one of the seven areas that protect your device and let you specify how you want your device protected in Windows Security Center. The seven areas include-

Virus & threat protectionAccount protectionFirewall & network protectionApp & browser controlDevice securityDevice performance & healthFamily options.

Generally, Device Security gives you greater insight into the security features integrated into your Windows device. The page provides you with status reporting and management of security features built into your devices – including toggling features on to provide enhanced protections. What you see in ‘Device Security’ will depend on the security features that come built into your device. On this panel, one of the following messages will be seen, depending on your device’s system configuration:

Your device meets the requirements for standard hardware securityYour device meets the requirements for enhanced hardware securityYour device exceeds the requirements for enhanced hardware securityStandard hardware security not supported.

Typically, the features available are-

This is where you’ll also see any relevant error messages about your security processor: This area can be hidden from users. This can be useful if, as an admin, you don’t want them to see or have access to this area. If you choose to hide the Account protection area, it will no longer appear on the home page of the Windows Security Center, and its icon will not be shown on the navigation bar on the side of the app.

Messages you may see in Device Security

Your device meets the requirements for standard hardware security

This means your device supports memory integrity and core isolation and also has:

TPM 2.0 (also referred to as your security processor)Secure boot enabledDEPUEFI MAT

Your device meets the requirements for enhanced hardware security

This means that in addition to meeting all the requirements of standard hardware security, your device also has memory integrity turned on.

Your device has all Secured-core PC features enabled

This means that in addition to meeting all the requirements of enhanced hardware security, your device also has System Management Mode (SMM) protection turned on.

Standard hardware security not supported

This means that your device does not meet at least one of the requirements of standard hardware security.

How to Show or Hide Device Security

Show or Hide Device Security via GPEDIT

Hide Device Security via Registry

Show Device Security via Registry

You can click here to download the zipped Registry files from our servers.