Files
rb/cg-disable.ps1
T
igodwin 314f6cf7f8 Initial runbook repo: Open Dental SMB credential fix + conventions
- README: purpose, hand-typeable fetch usage, naming + placeholder conventions
- CONTRIBUTING: public-repo sanitization rule (procedures only, no particulars)
- _template.ps1: iex-safe script convention (Read-Host, no param, admin check)
- od-smb-cred.md: Open Dental SMB stored-credential fix
- cg-disable.ps1: standalone Credential Guard disable + reboot

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 11:54:50 -07:00

60 lines
2.2 KiB
PowerShell

<#
.SYNOPSIS
Disable Windows Credential Guard, then reboot (prompts to confirm).
.DESCRIPTION
Credential Guard blocks replay of saved Credential Manager entries — the
classic "works after a manual Explorer connect, breaks on restart" SMB
symptom. This clears the VBS/Credential Guard flags and reboots to apply.
Enabled by default on Windows 11 22H2+ on entitled SKUs (Enterprise /
Business), not plain Pro.
.NOTES
Run via: irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/cg-disable.ps1 | iex
Referenced by od-smb-cred.md, Step 3.
If Credential Guard is still running after reboot, it was enabled with a
UEFI lock (needs the bcdedit / physical-presence removal), or MDM policy is
re-enabling it — align with the environment baseline instead of fighting it
locally.
#>
$ErrorActionPreference = 'Stop'
$isAdmin = ([Security.Principal.WindowsPrincipal] `
[Security.Principal.WindowsIdentity]::GetCurrent()
).IsInRole([Security.Principal.WindowsBuiltinRole]::Administrator)
if (-not $isAdmin) {
Write-Warning 'This script needs an elevated PowerShell session. Re-run as Administrator.'
return
}
Write-Host '== Disable Credential Guard ==' -ForegroundColor Cyan
Write-Host 'This clears the LsaCfgFlags / DeviceGuard Credential Guard flags and reboots.' -ForegroundColor Yellow
if ((Read-Host 'Proceed? (y/N)') -ne 'y') {
Write-Host 'Aborted. No changes made.'
return
}
try {
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" `
/v LsaCfgFlags /t REG_DWORD /d 0 /f | Out-Null
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\CredentialGuard" `
/v Enabled /t REG_DWORD /d 0 /f | Out-Null
Write-Host 'Flags cleared.' -ForegroundColor Green
}
catch {
Write-Warning "Failed to write registry: $($_.Exception.Message)"
return
}
Write-Host ''
Write-Host 'A reboot is required. After reboot, re-run msinfo32 and confirm' -ForegroundColor Yellow
Write-Host 'Credential Guard is no longer listed under Virtualization-based security.' -ForegroundColor Yellow
if ((Read-Host 'Reboot now? (y/N)') -eq 'y') {
shutdown /r /t 0
} else {
Write-Host 'Skipped reboot. Changes apply on next restart.'
}