Windows 10: LSASS.DMP still have my credential after enabling Credential Guard

Discus and support LSASS.DMP still have my credential after enabling Credential Guard in AntiVirus, Firewalls and System Security to solve the problem; Hi, I might sound noob but want to clarify something regarding Credential Guard. Scenario: I have a domain joined system for a year now and... Discussion in 'AntiVirus, Firewalls and System Security' started by PraveshJanartha, Mar 12, 2021.

  1. LSASS.DMP still have my credential after enabling Credential Guard


    Hi,


    I might sound noob but want to clarify something regarding Credential Guard.


    Scenario:


    I have a domain joined system for a year now and recently I enabled Credential Guard to test and play around with it. Output below shows that CredGuard is enabled:


    PS C:\temp> .\DG_Readiness_Tool.ps1 -Ready

    ###########################################################################

    Readiness Tool Version 3.7.2 Release.

    Tool to check if your device is capable to run Device Guard and Credential Guard.

    ###########################################################################

    ###########################################################################

    OS and Hardware requirements for enabling Device Guard and Credential Guard

    1. OS SKUs: Available only on these OS Skus - Enterprise, Server, Education and Enterprise IoT

    2. Hardware: Recent hardware that supports virtualization extension with SLAT

    To learn more please visit: https://aka.ms/dgwhcr

    ###########################################################################

    Credential-Guard is enabled and running.

    HVCI is enabled and running.

    Config-CI is enabled and running. Enforced mode

    HVCI, Credential Guard, and Config CI are enabled and running.


    Question:

    After enabling CredGuard, I dumped lsass.exe process and run it through Mimikatz to see what information it captures and it was still showing NTLM hash and clear text password. So what is the problem here? Why it is not preventing system from storing passwords in memory?



    :)
     
    PraveshJanartha, Mar 12, 2021
    #1
  2. Brink Win User

    Credential Guard lab companion


    Source: Credential Guard lab companion Datacenter and Private Cloud Security Blog


    See also:
     
    Brink, Mar 12, 2021
    #2
  3. Credential Guard

    When will Credential Guard be supported on the same Windows 10 Enterprise device as Barkly and VMWare Workstation Pro.

    It would be nice to be able to run these products without sacrificing Credential Guard.

    Moved from Insider
     
    IvanPiacun, Mar 12, 2021
    #3
  4. Ramhound Win User

    LSASS.DMP still have my credential after enabling Credential Guard

    VMware Workstation can be run after disabling Device/Credential Guard

    Windows Sandbox cannot be enabled on Windows 10 Home. The workaround you most likely used, does not even work, and has never actually worked. However, when you attempted to enable Windows Sandbox, it also enabled Credential Guard and Device Guard.

    The first thing you need to backup any critical files you cannot live without. Depending on the state of your system you might decide it's time to simply reinstall Windows 10 Home. An alternative is to upgrade to Windows 10 Professional so you can Enable Windows Sandbox then disable it properly. The following suggestion was written against an assumption that Windows Sandbox was properly enabled and not left in a broken state due to a workaround solution on Windows 10 Home.

    Source:

     
    Ramhound, Mar 12, 2021
    #4
Thema:

LSASS.DMP still have my credential after enabling Credential Guard

Loading...
  1. LSASS.DMP still have my credential after enabling Credential Guard - Similar Threads - LSASS DMP still

  2. Credential guard not running

    in Windows 10 Gaming
    Credential guard not running: After the newest update Credential guard disappeared from Windows Defender. Registry shows it`s turned on but it`s not present in the Core Isolation tab. System info doesn`t show it as a running service....
  3. Credential guard not running

    in Windows 10 Software and Apps
    Credential guard not running: After the newest update Credential guard disappeared from Windows Defender. Registry shows it`s turned on but it`s not present in the Core Isolation tab. System info doesn`t show it as a running service....
  4. Credential Guard Shows as Not Running

    in Windows 10 Gaming
    Credential Guard Shows as Not Running: In our domain, our computers are set up to have Credential Guard enabled with UEFI lock. This has been working without issue. I noticed on one computer running Windows 11 22H2, latest build that Credential Guard shows as not running in in System Information:Trying to...
  5. Credential Guard Shows as Not Running

    in Windows 10 Software and Apps
    Credential Guard Shows as Not Running: In our domain, our computers are set up to have Credential Guard enabled with UEFI lock. This has been working without issue. I noticed on one computer running Windows 11 22H2, latest build that Credential Guard shows as not running in in System Information:Trying to...
  6. Defender Credential Guard issue

    in AntiVirus, Firewalls and System Security
    Defender Credential Guard issue: Hi, one of our users is having an issue with RDP and Credential Guard....I made sure it is disabled and followed all the steps I've found in numerous sites registry, GPO, etc.. I even check MS Intune and it seems disabled there. See screenshot of the error....any ideas?...
  7. Device/Credential Guard are not compatible.

    in Windows 10 Network and Sharing
    Device/Credential Guard are not compatible.: I have to use VMware Workstation for some reason but it says Device/Credential Guard are not compatible. So from the research I got to know that first I have to disable the Credential Guard then I maybe able to use VMware Workstation, And for that I need a Group Policy...
  8. Verify if Credential Guard is Enabled or Disabled in Windows 10

    in Windows 10 Tutorials
    Verify if Credential Guard is Enabled or Disabled in Windows 10: How to: Verify if Credential Guard is Enabled or Disabled in Windows 10 How to Verify if Credential Guard is Enabled or Disabled in Windows 10 [img] Information Credential Guard uses virtualization-based security to isolate secrets so that only privileged system...
  9. Enable or Disable Credential Guard in Windows 10

    in Windows 10 Tutorials
    Enable or Disable Credential Guard in Windows 10: How to: Enable or Disable Credential Guard in Windows 10 How to Enable or Disable Credential Guard in Windows 10 Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Unauthorized access to these...
  10. Credential Guard lab companion

    in Windows 10 News
    Credential Guard lab companion: If you have heard about Credential Guard in Windows Server 2016 (and in Windows 10), but do not have an environment to try it out, here is a lab environment we built for you to play. Lab access The link will lead you to a sign up page, after that, you will see the...