Browsing the internet inherently involves security risks. Even with robust antivirus software, sophisticated malware, phishing attacks, and zero-day vulnerabilities can sometimes bypass traditional security measures. If an employee or user inadvertently clicks a malicious link or downloads a compromised file, the entire system and corporate network can be exposed.
Microsoft Defender Application Guard (MDAG) provides a powerful, hardware-based solution to this problem. Instead of relying solely on software-based scanning, Application Guard uses Microsoft’s Hyper-V virtualisation technology. When you open a website in Application Guard, the Microsoft Edge browser runs inside a secure, lightweight virtual machine. This virtual container is completely isolated from your host operating system, local storage, memory, and corporate network.
If a user encounters a malicious website while using Application Guard, the malware is trapped inside the virtual container. The moment the user closes the browser session, the container is destroyed, and the malware is eradicated without ever touching the host Windows 11 system.
In this guide, you will learn the requirements for Microsoft Defender Application Guard, how to enable it on Windows 11, and how to use it for secure browsing.
Requirements for Microsoft Defender Application Guard
Because Application Guard relies on hardware-level virtualisation, it is not available on all Windows 11 PCs. Before attempting to enable the feature, ensure your system meets the following prerequisites:
- Operating System: Windows 11 Pro, Enterprise, or Education edition. (Application Guard is not officially supported on Windows 11 Home).
- Hardware Virtualisation: Virtualisation must be enabled in your computer’s UEFI/BIOS settings (Look for Intel VT-x or AMD-V).
- Processor: A 64-bit CPU with minimum 4 cores.
- RAM: At least 8 GB of RAM (16 GB recommended for smooth performance).
- Storage: At least 5 GB of free space on a Solid State Drive (SSD).
Step 1: Enable Hardware Virtualisation in BIOS/UEFI
If you have not already enabled hardware virtualisation, you must do so before Windows will allow you to install Application Guard. The exact steps vary depending on your computer manufacturer, but the general process is:
- Restart your PC.
- During the boot process, repeatedly press the designated setup key (usually F2, F10, F12, Delete, or Esc) to enter the BIOS/UEFI.
- Navigate to the Security, System Configuration, or Advanced tab.
- Look for a setting named Intel Virtualization Technology (VT-x), AMD-V, or SVM Mode and change it to Enabled.
- Save your changes (usually F10) and exit. The computer will restart into Windows.
Step 2: Install the Application Guard Feature in Windows 11
Once virtualisation is confirmed, you need to add the Application Guard feature via the Windows Control Panel.
- Click the Start button, type Control Panel, and press Enter.
- Change the View by setting in the top right corner to Category.
- Click on Programs, then select Turn Windows features on or off.
- A small “Windows Features” window will appear. Scroll down the list until you find Microsoft Defender Application Guard.
- Check the box next to Microsoft Defender Application Guard.
- Click OK. Windows will now search for the required files and apply the changes. This process may take a minute or two.
- Once complete, Windows will prompt you to restart your computer. Click Restart now to finalise the installation.
Step 3: How to Use Application Guard in Microsoft Edge
After your PC restarts, Microsoft Defender Application Guard is integrated directly into the Microsoft Edge browser. Using it is very similar to opening an InPrivate (incognito) window, but with significantly stronger security.
- Open the Microsoft Edge browser.
- Click the three-dot menu icon (Settings and more) in the top-right corner of the browser window.
- Select New Application Guard window from the dropdown menu.
- A new Edge window will open. The first time you launch this, it may take 10 to 30 seconds as Windows spins up the isolated Hyper-V container in the background.
You can easily identify that you are browsing securely. The Application Guard window will have a distinct orange shield icon in the top left corner of the tab bar. Furthermore, the Edge taskbar icon will also display a small shield.
Understanding the Limitations of the Isolated Session
Because the Application Guard session is running in a locked-down virtual container, several standard browser features are intentionally restricted to protect the host machine:
- No persistent data: Cookies, browsing history, and saved passwords are not saved when the session ends. Once you close the window, all data is permanently destroyed.
- Restricted file downloads: By default, any files downloaded within the Application Guard session cannot be moved to your main computer’s hard drive. (Enterprise administrators can configure policies to allow this, but it is disabled by default for standalone setups).
- No copy/paste: Copying text or images from the Application Guard window to your main desktop (and vice versa) may be restricted, preventing data exfiltration or malware transfer via the clipboard.
- No extensions: Most browser extensions are disabled within the secure session to prevent them from executing malicious scripts.
When Should You Use Application Guard?
You do not need to use Application Guard for your daily web browsing; the performance overhead and restrictions make it impractical for checking known safe sites. Instead, reserve Application Guard for high-risk scenarios:
- Opening a link from an unverified or suspicious email.
- Researching potentially unsafe topics or visiting unfamiliar forums.
- Testing a URL that you suspect might be a phishing attempt.
- Browsing when connected to untrusted public Wi-Fi networks where man-in-the-middle attacks are a concern.
By utilising Microsoft Defender Application Guard for these specific tasks, you create a robust, hardware-enforced barrier that ensures malicious code remains entirely separate from your valuable data and operating system.