Skip to content

Only authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems.

An XCCDF Rule

Description

Allowing other operating systems to run on a secure system may allow users to circumvent security. For Hyper-V, preventing unauthorized users from being assigned to the Hyper-V Administrators group will prevent them from accessing or creating virtual machines on the system. The Hyper-V Hypervisor is used by virtualization-based Security features such as Credential Guard on Windows 11; however, it is not the full Hyper-V installation.

ID
SV-253271r958702_rule
Version
WN11-00-000080
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

For Hyper-V, remove any unauthorized groups or user accounts from the "Hyper-V Administrators" group.

For hosted hypervisors other than Hyper-V, restrict access to create or run virtual machines to authorized user accounts only.