6df8a53196
- Move _template.ps1 and cg-disable.ps1 into scripts/ - Update all fetch/run URLs and doc links to scripts/ paths - Rework README layout/naming section; add as-is/no-warranty disclaimer Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
60 lines
2.2 KiB
PowerShell
60 lines
2.2 KiB
PowerShell
<#
|
|
.SYNOPSIS
|
|
Disable Windows Credential Guard, then reboot (prompts to confirm).
|
|
|
|
.DESCRIPTION
|
|
Credential Guard blocks replay of saved Credential Manager entries — the
|
|
classic "works after a manual Explorer connect, breaks on restart" SMB
|
|
symptom. This clears the VBS/Credential Guard flags and reboots to apply.
|
|
|
|
Enabled by default on Windows 11 22H2+ on entitled SKUs (Enterprise /
|
|
Business), not plain Pro.
|
|
|
|
.NOTES
|
|
Run via: irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/scripts/cg-disable.ps1 | iex
|
|
Referenced by od-smb-cred.md, Step 3.
|
|
|
|
If Credential Guard is still running after reboot, it was enabled with a
|
|
UEFI lock (needs the bcdedit / physical-presence removal), or MDM policy is
|
|
re-enabling it — align with the environment baseline instead of fighting it
|
|
locally.
|
|
#>
|
|
|
|
$ErrorActionPreference = 'Stop'
|
|
|
|
$isAdmin = ([Security.Principal.WindowsPrincipal] `
|
|
[Security.Principal.WindowsIdentity]::GetCurrent()
|
|
).IsInRole([Security.Principal.WindowsBuiltinRole]::Administrator)
|
|
if (-not $isAdmin) {
|
|
Write-Warning 'This script needs an elevated PowerShell session. Re-run as Administrator.'
|
|
return
|
|
}
|
|
|
|
Write-Host '== Disable Credential Guard ==' -ForegroundColor Cyan
|
|
Write-Host 'This clears the LsaCfgFlags / DeviceGuard Credential Guard flags and reboots.' -ForegroundColor Yellow
|
|
if ((Read-Host 'Proceed? (y/N)') -ne 'y') {
|
|
Write-Host 'Aborted. No changes made.'
|
|
return
|
|
}
|
|
|
|
try {
|
|
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" `
|
|
/v LsaCfgFlags /t REG_DWORD /d 0 /f | Out-Null
|
|
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\CredentialGuard" `
|
|
/v Enabled /t REG_DWORD /d 0 /f | Out-Null
|
|
Write-Host 'Flags cleared.' -ForegroundColor Green
|
|
}
|
|
catch {
|
|
Write-Warning "Failed to write registry: $($_.Exception.Message)"
|
|
return
|
|
}
|
|
|
|
Write-Host ''
|
|
Write-Host 'A reboot is required. After reboot, re-run msinfo32 and confirm' -ForegroundColor Yellow
|
|
Write-Host 'Credential Guard is no longer listed under Virtualization-based security.' -ForegroundColor Yellow
|
|
if ((Read-Host 'Reboot now? (y/N)') -eq 'y') {
|
|
shutdown /r /t 0
|
|
} else {
|
|
Write-Host 'Skipped reboot. Changes apply on next restart.'
|
|
}
|