Microsoft rows back with VBS-Enlave announcement

Microsoft has specified plans for VBS-Enklave announcement in older Windows versions. Existing applications will continue to be supported as long as no new signing is required. The change affects Windows 11 23H2 and previous versions.
VBS enclaves are partly preserved
Microsoft has partially revised his decision to dismiss VBS enclaves in older Windows versions. Under certain conditions, the safety function in Windows 11 23H2 and previous Versions continue to support. This adaptation follows the original announcement in April, which caused concerns among developers and security experts.
What are VBS enclaves and why are they important?
VBS enclaves (virtualization-based security Enclaves) represent a central security mechanism in Windows 11. They enable isolated environments for sensitive data and program code, which prevents unauthorized access by other applications or the operating system. This technology is used in the Microsoft Azure SQL Database and the Windows 11 recall function.
The new regulation in detail
The strength of VBS enclaves lies in the establishment of virtual levels of trust (VTL) within a software-based Trust Execution Environment (tea). A big advantage is that you do not require any special hardware and work on all supported Windows PCs. The original decision had therefore caused irritation, since Microsoft had not given a specific reason for setting the function in older systems.
The change was discovered by May 5th from Online magazine Neowin. Accordingly, the support of existing enclaves, which were signed with the extended key usage (EKU) 1.3.6.1.4.1.311.76.57.1.15, have existed as long as no changes are made that require new signing. If new signing is necessary, the new EKU is used, and the enclave is only supported on Windows 11 24H2 and later versions. The regulation specifically affects the following operating systems:
- Windows 10, version 22h2
- Windows 11, version 22h2
- Windows 11, version 23h2
- Windows 11, version 24h2 and later
Effects for users and developers
For most home users, the effects of this change remain manageable. Windows 11 23H2 will fall out of the regular support cycle in November 2025. Developers, on the other hand, have to take this new regulation into account, especially if they maintain applications that use VBS enclaves.