Speculative fix for bug #1409 as per comment #4. Can't test until can build kernel.
PlatSecEnforcement ON
PlatSecDiagnostics ON
PlatSecDisabledCaps -TCB+CommDD-PowerMgmt+MultimediaDD-ReadDeviceData+WriteDeviceData-DRM+TrustedUI-ProtServ+DiskAdmin-NetworkControl+AllFiles-SwEvent+NetworkServices-LocalServices+ReadUserData-WriteUserData+Location