Use this tool to see if your hardware is ready for Device Guard and Credential Guard. You can also use this to enable Device Guard or Credential Guard.
This tool is a Windows PowerShell script that needs to run with elevated permissions. It will work with Windows 10 (beginning with version 1607) and Windows Server 2016.
You can use this tool in the following ways:
Check if the device can run Device Guard or Credential Guard
Check if the device is compatible with the Hardware Lab Kit tests that are ran by partners
Enable and disable Device Guard or Credential Guard
Check the status of Device Guard or Credential Guard on the device
Integrate with System Center Configuration Manager or any other deployment mechanism to configure registry settings that reflect the device capabilities
Use an embedded ConfigCI policy in audit mode that can be used by default to enable Device Guard when a custom policy is not provided
Usage:
DG_Readiness.ps1 –[Enable/Disable/Capable/Ready] –[DG/CG/HVCI/HLK] -Path <ConfigCI policy> -AutoReboot