The only one of those that is locked behind a specific Windows edition is Credential Guard, which only works on Enterprise and Education because it has to do with auth tokens of the domain, not local windows login AFAIK
The rest are locked behind hardware features like TPM and UEFI settings like secure boot.
I hate Microslop as much as the next person, but they do actually try to push their security features on everyone because of the reputation they've had as the most insecure OS.