Status: read-only protection inventory and inconclusive. Nothing was implemented or applied on the lab machine. No protection, exclusion, scan, firewall profile or rule, service, VBS, Memory Integrity, Credential Guard, code-integrity policy, BitLocker, Secure Boot, registry, Group Policy, MDM, driver, task, startup application, OEM control, update, recovery, or management setting changed.

The evidence question

Does the current Defender, firewall, virtualization-based security, code-integrity, encryption, and Secure Boot inventory identify one supported security-preserving change that improves startup or responsiveness?

No. The inventory proves that several protections are active. It contains no startup/readiness workflow, Defender performance recording, WPR trace, repeated raw run, median, instrumentation-overhead qualification, or accepted decision rule that attributes a customer-visible delay to them.

BitLocker and Secure Boot checks returned access denied without elevation. Their state is unknown, not off.

Exact observed protection inventory

SurfaceObserved stateLimit
Microsoft Defender AntivirusNormal mode; antivirus, antispyware, real-time, behavior, IOAV, on-access, network inspection, and tamper protection enabledNo scan or performance recording ran
Defender platform4.18.26060.3008; signatures current at observation timeConfiguration is not scan-cost attribution
Windows Firewall effective ActiveStoreDomain, Private, and Public enabled; default inbound Block; default outbound AllowRules and network workflows were not enumerated
Firewall profile optionsInbound and local rules allowed; notifications on; allowed/blocked traffic logging offResultant policy can come from local, service, CSP, MDM, or Group Policy stores
Virtualization-based securityStatus code 2: enabled and runningPolicy origin was not identified
Memory IntegrityConfigured and runningDriver and application compatibility still matters
Credential GuardRunning-service code 1 reported by Win32_DeviceGuardLicense and configuration history were not inferred
Kernel/user-mode code integrityEnforcement status 2: enforcedThe specific policy was not identified
BitLockerUnknown: access denied without elevationNo protectors or recovery material were read
Secure BootUnknown: access denied without elevationNo firmware or boot setting changed

The Defender performance analyzer commands are installed. The automation did not start a recording because Microsoft requires an elevated recording and the resulting ETL can expose file and process paths. A future run needs synthetic data, approved storage and retention, redaction, explicit stop/cleanup, and overhead measurement.

Defender exclusions were deliberately not enumerated. Microsoft says every exclusion is a protection gap and should address a demonstrated problem rather than a guessed one.

Documented defaults and dependencies

Microsoft defines the firewall ActiveStore as the resultant set of all applicable policy stores. Its guidance recommends keeping the default firewall settings, including default inbound blocking, and says not to stop the Windows Firewall service MpsSvc.

Memory Integrity uses VBS and the Windows hypervisor to isolate kernel code-integrity decisions. Microsoft reports better operation on processors with MBEC or GMET and warns that incompatible drivers or applications can malfunction. The lab WMI surface reported MBEC/GMET as available, but availability is not a workload benchmark.

Credential Guard isolates qualifying credentials with VBS and has edition, license, firmware, and authentication compatibility boundaries. Microsoft notes that Windows 11 Pro systems can still report VBS or Credential Guard after an earlier eligible configuration. The observed running code therefore does not establish entitlement or management origin.

Microsoft says BitLocker overhead is normally small and depends on storage throughput. That general statement is not a measurement of this ZBook, particularly while its protection method remains unknown.

Evidence ledger

Documented facts

  • Get-MpComputerStatus reports Defender real-time and tamper-protection state.
  • Defender's analyzer attributes antimalware-engine scan duration to paths, files, extensions, and processes.
  • Win32_DeviceGuard reports VBS, Memory Integrity, Credential Guard, and code-integrity states.
  • Microsoft recommends keeping Windows Firewall enabled and treating exclusions as protection gaps.

Lab measurements

One non-elevated, read-only inventory was captured on AC. No security trace, scan, startup/readiness run, responsiveness workload, or performance benchmark ran.

Hypotheses

Defender, isolation, code integrity, authentication, or encryption work may affect a specific workflow. A supported application, driver, signing, data-layout, or workflow correction may be safer than changing protection. Neither hypothesis is tested.

Unresolved questions

  • Which synthetic workflow reproduces a delay?
  • What overhead does the Defender recorder add?
  • What policy produced the Credential Guard and code-integrity states?
  • What are the BitLocker and Secure Boot states?

How to measure without reducing protection

  1. Define one synthetic workflow with start, readiness, reset, timeout, and failure rules.
  2. Record the protection state at every run boundary without collecting identities, recovery material, exclusions, or customer content.
  3. In a supervised elevated window, record only the reproduction with New-MpPerformanceRecording and analyze it with Get-MpPerformanceReport.
  4. Interleave control and recorded runs while keeping every protection enabled, then preserve raw runs, failures, medians, variability, power, and thermal state.
  5. If a specific hotspot is demonstrated, investigate the supported application, driver, file layout, signing, or workflow correction first.

An antivirus exclusion is not a default performance setting. It remains a protection reduction and requires a separate, specific security review even when a trace identifies scan cost.

Compatibility and rollback status

The observation applies only to the recorded HP ZBook Firefly 14 inch G8, Windows 11 Pro build 26200, BIOS T76 01.24.02, Defender platform/signature state, effective firewall policy, and VBS state.

No configuration changed, so rollback is not applicable. A future change still requires support detection, exact original-state capture, dry run, apply, configuration and workflow verification, structured logging, idempotence, exact rollback, rollback verification, and reboot-persistence testing.

Defender/EDR, firewall, VBS, Memory Integrity, Credential Guard, code integrity, BitLocker, Secure Boot, Windows Update, recovery, management, HP security/OEM components, services, tasks, startup applications, policies, registry, drivers, and firmware remain untouched.

Primary sources

All sources were retrieved July 27, 2026.

YouTube briefing

Presenter: This hour read the ZBook's protection status without changing it.

Defender real-time and tamper protection are enabled. All three effective firewall profiles are enabled. VBS and Memory Integrity are running, and Windows also reports Credential Guard and code-integrity enforcement.

Those states do not prove a slowdown. No startup workflow, Defender recording, WPR trace, repeated run, median, or overhead measurement ran. BitLocker and Secure Boot remain unknown because their non-elevated checks were denied.

No protection was weakened and no performance gain is claimed. Layer 8 next investigates the boot path, services, scheduled tasks, background permissions, and startup applications with documentation and trace evidence before any change.

Read the complete source script

Source and next layer

The next hourly cycle position is layer 8: boot path, services, scheduled tasks, background permissions, and startup applications. Every item remains required until vendor documentation, dependency analysis, and boot-trace evidence establish a safe narrower state.

Back to all development updates