* BitLocker: Hard-drive encryption backed by TPM & Secure Boot
With the above two and DMA protection, physical access attacks become very difficult.
* Virtual Secure Mode (VSM) - separate OS running on the hypervisor that can perform sensitive operations. Which enables:
1. Device Guard - Runs code integrity protection, i.e. only allowing signed code to run, from within the VSM.
2. Credential Guard - Runs user-mode security subsystem (LSA) inside VSM.