Windows 10: LSASS.DMP still have my credential after enabling Credential Guard

Discus and support LSASS.DMP still have my credential after enabling Credential Guard in AntiVirus, Firewalls and System Security to solve the problem; Hi, I might sound noob but want to clarify something regarding Credential Guard. Scenario: I have a domain joined system for a year now and... Discussion in 'AntiVirus, Firewalls and System Security' started by PraveshJanartha, Mar 12, 2021.

  1. LSASS.DMP still have my credential after enabling Credential Guard


    Hi,


    I might sound noob but want to clarify something regarding Credential Guard.


    Scenario:


    I have a domain joined system for a year now and recently I enabled Credential Guard to test and play around with it. Output below shows that CredGuard is enabled:


    PS C:\temp> .\DG_Readiness_Tool.ps1 -Ready

    ###########################################################################

    Readiness Tool Version 3.7.2 Release.

    Tool to check if your device is capable to run Device Guard and Credential Guard.

    ###########################################################################

    ###########################################################################

    OS and Hardware requirements for enabling Device Guard and Credential Guard

    1. OS SKUs: Available only on these OS Skus - Enterprise, Server, Education and Enterprise IoT

    2. Hardware: Recent hardware that supports virtualization extension with SLAT

    To learn more please visit: https://aka.ms/dgwhcr

    ###########################################################################

    Credential-Guard is enabled and running.

    HVCI is enabled and running.

    Config-CI is enabled and running. Enforced mode

    HVCI, Credential Guard, and Config CI are enabled and running.


    Question:

    After enabling CredGuard, I dumped lsass.exe process and run it through Mimikatz to see what information it captures and it was still showing NTLM hash and clear text password. So what is the problem here? Why it is not preventing system from storing passwords in memory?



    :)
     
    PraveshJanartha, Mar 12, 2021
    #1
  2. Brink Win User

    Credential Guard lab companion


    Source: Credential Guard lab companion Datacenter and Private Cloud Security Blog


    See also:
     
    Brink, Mar 12, 2021
    #2
  3. Credential Guard

    When will Credential Guard be supported on the same Windows 10 Enterprise device as Barkly and VMWare Workstation Pro.

    It would be nice to be able to run these products without sacrificing Credential Guard.

    Moved from Insider
     
    IvanPiacun, Mar 12, 2021
    #3
  4. Ramhound Win User

    LSASS.DMP still have my credential after enabling Credential Guard

    VMware Workstation can be run after disabling Device/Credential Guard

    Windows Sandbox cannot be enabled on Windows 10 Home. The workaround you most likely used, does not even work, and has never actually worked. However, when you attempted to enable Windows Sandbox, it also enabled Credential Guard and Device Guard.

    The first thing you need to backup any critical files you cannot live without. Depending on the state of your system you might decide it's time to simply reinstall Windows 10 Home. An alternative is to upgrade to Windows 10 Professional so you can Enable Windows Sandbox then disable it properly. The following suggestion was written against an assumption that Windows Sandbox was properly enabled and not left in a broken state due to a workaround solution on Windows 10 Home.

    Source:

     
    Ramhound, Mar 12, 2021
    #4
Thema:

LSASS.DMP still have my credential after enabling Credential Guard

Loading...
  1. LSASS.DMP still have my credential after enabling Credential Guard - Similar Threads - LSASS DMP still

  2. Credential Guard is configured to run, but is not licensed. Credential Guard was not started.

    in Windows 10 Gaming
    Credential Guard is configured to run, but is not licensed. Credential Guard was not started.: I am, since a fresh installation of Windows 11 23H2 and even after installing all applicable updates get these warnings in Event Viewer.Credential Guard is configured to run, but is not licensed. Credential Guard was not started.So I go to GPEDIT, change "Turn on...
  3. Credential Guard is configured to run, but is not licensed. Credential Guard was not started.

    in Windows 10 Software and Apps
    Credential Guard is configured to run, but is not licensed. Credential Guard was not started.: I am, since a fresh installation of Windows 11 23H2 and even after installing all applicable updates get these warnings in Event Viewer.Credential Guard is configured to run, but is not licensed. Credential Guard was not started.So I go to GPEDIT, change "Turn on...
  4. Credential Guard is configured to run, but is not licensed. Credential Guard was not...

    in Windows 10 Gaming
    Credential Guard is configured to run, but is not licensed. Credential Guard was not...: Hi, I have a fresh installed Windows 11 24H2 Pro system without any 3rd party Application. But Credential Guard is not running verified in Windows Security, systeminfo32, PS Win32_DeviceGuard.In event log there is Event ID 6147 LSA LSAsrv "Credential Guard is configured to...
  5. Credential Guard is configured to run, but is not licensed. Credential Guard was not...

    in Windows 10 Software and Apps
    Credential Guard is configured to run, but is not licensed. Credential Guard was not...: Hi, I have a fresh installed Windows 11 24H2 Pro system without any 3rd party Application. But Credential Guard is not running verified in Windows Security, systeminfo32, PS Win32_DeviceGuard.In event log there is Event ID 6147 LSA LSAsrv "Credential Guard is configured to...
  6. Disabling credential guard

    in Windows 10 Gaming
    Disabling credential guard: Good day MS. Team, I want to disable the credential guard on my new windows 11 PC. but if I go to Administrative Template > System > I do not see Device Guide. I also DO NOT see Hyper-V under Turn Windows feature On and Off , Is there anything I can do to access these two...
  7. Disabling credential guard

    in Windows 10 Software and Apps
    Disabling credential guard: Good day MS. Team, I want to disable the credential guard on my new windows 11 PC. but if I go to Administrative Template > System > I do not see Device Guide. I also DO NOT see Hyper-V under Turn Windows feature On and Off , Is there anything I can do to access these two...
  8. Credential guard not running

    in Windows 10 Gaming
    Credential guard not running: After the newest update Credential guard disappeared from Windows Defender. Registry shows it`s turned on but it`s not present in the Core Isolation tab. System info doesn`t show it as a running service....
  9. Credential guard not running

    in Windows 10 Software and Apps
    Credential guard not running: After the newest update Credential guard disappeared from Windows Defender. Registry shows it`s turned on but it`s not present in the Core Isolation tab. System info doesn`t show it as a running service....
  10. Enable or Disable Credential Guard in Windows 10

    in Windows 10 Tutorials
    Enable or Disable Credential Guard in Windows 10: How to: Enable or Disable Credential Guard in Windows 10 How to Enable or Disable Credential Guard in Windows 10 Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Unauthorized access to these...