{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/enable-credential-guard-after-testing-authentication-dependencies/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/",
        "slug": "enable-credential-guard-after-testing-authentication-dependencies",
        "url": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/enable-credential-guard-after-testing-authentication-dependencies/"
        },
        "title": "Enable Credential Guard only after testing authentication dependencies",
        "summary": "Windows Credential Guard isolates selected secrets with virtualization-based security, but legacy protocols, delegation, security packages, remote access, firmware, virtualization, and applications can change behavior. Discover and pilot before enforcement.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-17T12:58:00+00:00",
        "modified_at": "2026-08-17T19:22:09+00:00",
        "reviewed_on": "2026-08-17",
        "reading_minutes": 3,
        "word_count": 639,
        "potentially_affected": "Supported Windows 10, Windows 11 and Windows Server devices; virtualization-based security, Secure Boot and TPM; Kerberos, NTLM, Credential Manager, CredSSP, delegation, RDP, VPN and Wi-Fi authentication; security packages; hypervisors; help desk; and recovery.",
        "dse_recommendation": "Confirm supported hardware and operating systems, inventory authentication and credential dependencies, establish a compatible firmware and virtualization baseline, pilot representative devices and workflows, collect errors and user impact, remediate dependencies, stage enforcement, and retain recovery procedures.",
        "primary_source": {
            "name": "Microsoft Learn: Considerations and known issues when using Credential Guard",
            "url": "https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: Credential Guard changes how selected credentials are available</h2>\n<p>Microsoft’s <a href=\"https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues\" target=\"_blank\" rel=\"noopener noreferrer\">Credential Guard considerations and known-issues guidance</a> documents compatibility implications and scenarios that require planning. Credential Guard uses virtualization-based security, and enabling or disabling it can interact with operating-system defaults, policy, firmware, virtual machines, and deployment method.</p>\n<p>Microsoft’s <a href=\"https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/how-it-works\" target=\"_blank\" rel=\"noopener noreferrer\">technical overview</a> explains that isolated LSA stores selected Kerberos, NTLM, and Credential Manager secrets outside the ordinary operating-system process using VBS. It also states protection limits. Credential Guard does not protect credentials managed outside Windows protections, keyloggers, physical attacks, the Active Directory database on a domain controller, or every credential supplied to legacy authentication.</p>\n<p>The documentation describes protocol effects: certain uses of NTLMv1, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, and DES can no longer use signed-in credentials as before. Exact defaults, hardware requirements, support, and behavior vary by Windows edition, version, device role, virtualization platform, and policy. Review current Microsoft and product-vendor documentation for the target fleet.</p>\n\n<h2>DSE recommendation: use deployment to expose and retire weak dependencies</h2>\n<p>Do not begin by forcing the policy across the fleet. Build a readiness inventory that connects devices to business workflows and authentication dependencies. Include privileged workstations, standard laptops, shared workstations, kiosks, jump hosts, servers used interactively, virtual desktops, VPN, Wi-Fi, RDP, file and print, line-of-business applications, smart cards, third-party credential providers, endpoint security, and backup or recovery tools.</p>\n<ol>\n<li><strong>Confirm platform readiness.</strong> Verify supported Windows edition and build, firmware, Secure Boot, virtualization extensions, TPM state where applicable, VBS and hypervisor compatibility, driver and security-software support, and virtual-machine configuration. Remediate unsupported firmware and drivers before attributing failures to authentication.</li>\n<li><strong>Find legacy protocols.</strong> Use approved directory, network, endpoint, and application evidence to identify NTLM versions, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, DES, saved credentials, and non-Microsoft security packages. Validate each dependency with its owner; a log event does not by itself prove safe removal.</li>\n<li><strong>Define the pilot.</strong> Include each hardware model, Windows build, user type, location, network, privileged workflow, remote-access method, and critical application. Provide a control group, change window, support contact, stop threshold, and documented recovery that does not require an unavailable credential path.</li>\n<li><strong>Exercise real workflows.</strong> Test sign-in with and without domain connectivity, lock and unlock, password and authenticator change, VPN, Wi-Fi, RDP, file shares, print, administration, application single sign-on, scheduled work, sleep, hibernate, restart, patching, and disaster-recovery access. Include help-desk and break-glass procedures.</li>\n<li><strong>Observe and remediate.</strong> Collect supported Credential Guard state, VBS status, authentication events, application and driver errors, help-desk cases, latency, and fallback authentication. Fix the protocol or application where possible rather than creating broad exclusions that restore credential exposure.</li>\n<li><strong>Stage enforcement.</strong> Expand by well-understood rings, monitor after each wave, and pause on systemic failure. Keep policy ownership and rollback controlled. A device that reports the feature enabled but cannot perform its required recovery path is not production-ready.</li>\n</ol>\n<p>Separate Credential Guard from Remote Credential Guard, LSA protection, Windows Hello, and other related features in design and test records; they have different requirements and boundaries. Protect the hypervisor and host of virtual machines, because in-guest isolation does not defend against a privileged host attack.</p>\n<p>Retest after major Windows, firmware, hypervisor, VPN, security-agent, or application changes. The completion record should list supported devices, workflows exercised, remaining legacy dependencies, exceptions, and recovery results. Credential Guard reduces specific credential-theft paths; it is not a substitute for privileged-access separation, patching, phishing resistance, endpoint protection, or least privilege.</p>\n<p>Use an exit gate for every deployment ring: all required workflows pass, recovery was demonstrated, state reporting is reliable, support can recognize known errors, and every exception has an owner and end condition. Stop on widespread fallback prompts, lost remote administration, incompatible security software, or inability to boot and recover. Preserve diagnostic evidence, restore the approved configuration, remediate the dependency, and rerun the full ring.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>Microsoft, <a href=\"https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues\" target=\"_blank\" rel=\"noopener noreferrer\">Considerations and known issues when using Credential Guard</a>.</li>\n<li>Microsoft, <a href=\"https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/how-it-works\" target=\"_blank\" rel=\"noopener noreferrer\">How Credential Guard works</a>.</li>\n</ul>",
        "content_text": "Source facts: Credential Guard changes how selected credentials are available\nMicrosoft’s Credential Guard considerations and known-issues guidance documents compatibility implications and scenarios that require planning. Credential Guard uses virtualization-based security, and enabling or disabling it can interact with operating-system defaults, policy, firmware, virtual machines, and deployment method.\nMicrosoft’s technical overview explains that isolated LSA stores selected Kerberos, NTLM, and Credential Manager secrets outside the ordinary operating-system process using VBS. It also states protection limits. Credential Guard does not protect credentials managed outside Windows protections, keyloggers, physical attacks, the Active Directory database on a domain controller, or every credential supplied to legacy authentication.\nThe documentation describes protocol effects: certain uses of NTLMv1, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, and DES can no longer use signed-in credentials as before. Exact defaults, hardware requirements, support, and behavior vary by Windows edition, version, device role, virtualization platform, and policy. Review current Microsoft and product-vendor documentation for the target fleet.\n\nDSE recommendation: use deployment to expose and retire weak dependencies\nDo not begin by forcing the policy across the fleet. Build a readiness inventory that connects devices to business workflows and authentication dependencies. Include privileged workstations, standard laptops, shared workstations, kiosks, jump hosts, servers used interactively, virtual desktops, VPN, Wi-Fi, RDP, file and print, line-of-business applications, smart cards, third-party credential providers, endpoint security, and backup or recovery tools.\n\nConfirm platform readiness. Verify supported Windows edition and build, firmware, Secure Boot, virtualization extensions, TPM state where applicable, VBS and hypervisor compatibility, driver and security-software support, and virtual-machine configuration. Remediate unsupported firmware and drivers before attributing failures to authentication.\nFind legacy protocols. Use approved directory, network, endpoint, and application evidence to identify NTLM versions, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, DES, saved credentials, and non-Microsoft security packages. Validate each dependency with its owner; a log event does not by itself prove safe removal.\nDefine the pilot. Include each hardware model, Windows build, user type, location, network, privileged workflow, remote-access method, and critical application. Provide a control group, change window, support contact, stop threshold, and documented recovery that does not require an unavailable credential path.\nExercise real workflows. Test sign-in with and without domain connectivity, lock and unlock, password and authenticator change, VPN, Wi-Fi, RDP, file shares, print, administration, application single sign-on, scheduled work, sleep, hibernate, restart, patching, and disaster-recovery access. Include help-desk and break-glass procedures.\nObserve and remediate. Collect supported Credential Guard state, VBS status, authentication events, application and driver errors, help-desk cases, latency, and fallback authentication. Fix the protocol or application where possible rather than creating broad exclusions that restore credential exposure.\nStage enforcement. Expand by well-understood rings, monitor after each wave, and pause on systemic failure. Keep policy ownership and rollback controlled. A device that reports the feature enabled but cannot perform its required recovery path is not production-ready.\n\nSeparate Credential Guard from Remote Credential Guard, LSA protection, Windows Hello, and other related features in design and test records; they have different requirements and boundaries. Protect the hypervisor and host of virtual machines, because in-guest isolation does not defend against a privileged host attack.\nRetest after major Windows, firmware, hypervisor, VPN, security-agent, or application changes. The completion record should list supported devices, workflows exercised, remaining legacy dependencies, exceptions, and recovery results. Credential Guard reduces specific credential-theft paths; it is not a substitute for privileged-access separation, patching, phishing resistance, endpoint protection, or least privilege.\nUse an exit gate for every deployment ring: all required workflows pass, recovery was demonstrated, state reporting is reliable, support can recognize known errors, and every exception has an owner and end condition. Stop on widespread fallback prompts, lost remote administration, incompatible security software, or inability to boot and recover. Preserve diagnostic evidence, restore the approved configuration, remediate the dependency, and rerun the full ring.\n\nOfficial references\n\nMicrosoft, Considerations and known issues when using Credential Guard.\nMicrosoft, How Credential Guard works.",
        "content_markdown": "## Source facts: Credential Guard changes how selected credentials are available\n\nMicrosoft’s [Credential Guard considerations and known-issues guidance](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues) documents compatibility implications and scenarios that require planning. Credential Guard uses virtualization-based security, and enabling or disabling it can interact with operating-system defaults, policy, firmware, virtual machines, and deployment method.\n\nMicrosoft’s [technical overview](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/how-it-works) explains that isolated LSA stores selected Kerberos, NTLM, and Credential Manager secrets outside the ordinary operating-system process using VBS. It also states protection limits. Credential Guard does not protect credentials managed outside Windows protections, keyloggers, physical attacks, the Active Directory database on a domain controller, or every credential supplied to legacy authentication.\n\nThe documentation describes protocol effects: certain uses of NTLMv1, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, and DES can no longer use signed-in credentials as before. Exact defaults, hardware requirements, support, and behavior vary by Windows edition, version, device role, virtualization platform, and policy. Review current Microsoft and product-vendor documentation for the target fleet.\n\n## DSE recommendation: use deployment to expose and retire weak dependencies\n\nDo not begin by forcing the policy across the fleet. Build a readiness inventory that connects devices to business workflows and authentication dependencies. Include privileged workstations, standard laptops, shared workstations, kiosks, jump hosts, servers used interactively, virtual desktops, VPN, Wi-Fi, RDP, file and print, line-of-business applications, smart cards, third-party credential providers, endpoint security, and backup or recovery tools.\n\n- Confirm platform readiness. Verify supported Windows edition and build, firmware, Secure Boot, virtualization extensions, TPM state where applicable, VBS and hypervisor compatibility, driver and security-software support, and virtual-machine configuration. Remediate unsupported firmware and drivers before attributing failures to authentication.\n\n- Find legacy protocols. Use approved directory, network, endpoint, and application evidence to identify NTLM versions, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, DES, saved credentials, and non-Microsoft security packages. Validate each dependency with its owner; a log event does not by itself prove safe removal.\n\n- Define the pilot. Include each hardware model, Windows build, user type, location, network, privileged workflow, remote-access method, and critical application. Provide a control group, change window, support contact, stop threshold, and documented recovery that does not require an unavailable credential path.\n\n- Exercise real workflows. Test sign-in with and without domain connectivity, lock and unlock, password and authenticator change, VPN, Wi-Fi, RDP, file shares, print, administration, application single sign-on, scheduled work, sleep, hibernate, restart, patching, and disaster-recovery access. Include help-desk and break-glass procedures.\n\n- Observe and remediate. Collect supported Credential Guard state, VBS status, authentication events, application and driver errors, help-desk cases, latency, and fallback authentication. Fix the protocol or application where possible rather than creating broad exclusions that restore credential exposure.\n\n- Stage enforcement. Expand by well-understood rings, monitor after each wave, and pause on systemic failure. Keep policy ownership and rollback controlled. A device that reports the feature enabled but cannot perform its required recovery path is not production-ready.\n\nSeparate Credential Guard from Remote Credential Guard, LSA protection, Windows Hello, and other related features in design and test records; they have different requirements and boundaries. Protect the hypervisor and host of virtual machines, because in-guest isolation does not defend against a privileged host attack.\n\nRetest after major Windows, firmware, hypervisor, VPN, security-agent, or application changes. The completion record should list supported devices, workflows exercised, remaining legacy dependencies, exceptions, and recovery results. Credential Guard reduces specific credential-theft paths; it is not a substitute for privileged-access separation, patching, phishing resistance, endpoint protection, or least privilege.\n\nUse an exit gate for every deployment ring: all required workflows pass, recovery was demonstrated, state reporting is reliable, support can recognize known errors, and every exception has an owner and end condition. Stop on widespread fallback prompts, lost remote administration, incompatible security software, or inability to boot and recover. Preserve diagnostic evidence, restore the approved configuration, remediate the dependency, and rerun the full ring.\n\n## Official references\n\n- Microsoft, [Considerations and known issues when using Credential Guard](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues).\n\n- Microsoft, [How Credential Guard works](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/how-it-works)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/",
                "url": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-17"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Enable Credential Guard only after testing authentication dependencies",
                        "item": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/#article",
                "identifier": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/",
                "url": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/",
                "headline": "Enable Credential Guard only after testing authentication dependencies",
                "description": "Windows Credential Guard isolates selected secrets with virtualization-based security, but legacy protocols, delegation, security packages, remote…",
                "abstract": "Windows Credential Guard isolates selected secrets with virtualization-based security, but legacy protocols, delegation, security packages, remote access, firmware, virtualization, and applications can change behavior. Discover and pilot before enforcement.",
                "articleBody": "Source facts: Credential Guard changes how selected credentials are available\nMicrosoft’s Credential Guard considerations and known-issues guidance documents compatibility implications and scenarios that require planning. Credential Guard uses virtualization-based security, and enabling or disabling it can interact with operating-system defaults, policy, firmware, virtual machines, and deployment method.\nMicrosoft’s technical overview explains that isolated LSA stores selected Kerberos, NTLM, and Credential Manager secrets outside the ordinary operating-system process using VBS. It also states protection limits. Credential Guard does not protect credentials managed outside Windows protections, keyloggers, physical attacks, the Active Directory database on a domain controller, or every credential supplied to legacy authentication.\nThe documentation describes protocol effects: certain uses of NTLMv1, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, and DES can no longer use signed-in credentials as before. Exact defaults, hardware requirements, support, and behavior vary by Windows edition, version, device role, virtualization platform, and policy. Review current Microsoft and product-vendor documentation for the target fleet.\n\nDSE recommendation: use deployment to expose and retire weak dependencies\nDo not begin by forcing the policy across the fleet. Build a readiness inventory that connects devices to business workflows and authentication dependencies. Include privileged workstations, standard laptops, shared workstations, kiosks, jump hosts, servers used interactively, virtual desktops, VPN, Wi-Fi, RDP, file and print, line-of-business applications, smart cards, third-party credential providers, endpoint security, and backup or recovery tools.\n\nConfirm platform readiness. Verify supported Windows edition and build, firmware, Secure Boot, virtualization extensions, TPM state where applicable, VBS and hypervisor compatibility, driver and security-software support, and virtual-machine configuration. Remediate unsupported firmware and drivers before attributing failures to authentication.\nFind legacy protocols. Use approved directory, network, endpoint, and application evidence to identify NTLM versions, MS-CHAPv2, Digest, CredSSP, unconstrained delegation, DES, saved credentials, and non-Microsoft security packages. Validate each dependency with its owner; a log event does not by itself prove safe removal.\nDefine the pilot. Include each hardware model, Windows build, user type, location, network, privileged workflow, remote-access method, and critical application. Provide a control group, change window, support contact, stop threshold, and documented recovery that does not require an unavailable credential path.\nExercise real workflows. Test sign-in with and without domain connectivity, lock and unlock, password and authenticator change, VPN, Wi-Fi, RDP, file shares, print, administration, application single sign-on, scheduled work, sleep, hibernate, restart, patching, and disaster-recovery access. Include help-desk and break-glass procedures.\nObserve and remediate. Collect supported Credential Guard state, VBS status, authentication events, application and driver errors, help-desk cases, latency, and fallback authentication. Fix the protocol or application where possible rather than creating broad exclusions that restore credential exposure.\nStage enforcement. Expand by well-understood rings, monitor after each wave, and pause on systemic failure. Keep policy ownership and rollback controlled. A device that reports the feature enabled but cannot perform its required recovery path is not production-ready.\n\nSeparate Credential Guard from Remote Credential Guard, LSA protection, Windows Hello, and other related features in design and test records; they have different requirements and boundaries. Protect the hypervisor and host of virtual machines, because in-guest isolation does not defend against a privileged host attack.\nRetest after major Windows, firmware, hypervisor, VPN, security-agent, or application changes. The completion record should list supported devices, workflows exercised, remaining legacy dependencies, exceptions, and recovery results. Credential Guard reduces specific credential-theft paths; it is not a substitute for privileged-access separation, patching, phishing resistance, endpoint protection, or least privilege.\nUse an exit gate for every deployment ring: all required workflows pass, recovery was demonstrated, state reporting is reliable, support can recognize known errors, and every exception has an owner and end condition. Stop on widespread fallback prompts, lost remote administration, incompatible security software, or inability to boot and recover. Preserve diagnostic evidence, restore the approved configuration, remediate the dependency, and rerun the full ring.\n\nOfficial references\n\nMicrosoft, Considerations and known issues when using Credential Guard.\nMicrosoft, How Credential Guard works.",
                "datePublished": "2026-08-17T12:58:00+00:00",
                "dateModified": "2026-08-17T19:22:09+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/enable-credential-guard-after-testing-authentication-dependencies/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Enable Credential Guard only after testing authentication dependencies"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 639,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Learn: Considerations and known issues when using Credential Guard",
                    "url": "https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues"
                }
            }
        ]
    }
}