Microsoft Will Soon Enable Memory Integrity Protection on Eligible Windows 11 PCs

Windows 11 Hero image

Microsoft is preparing to enable memory integrity protection on eligible PCs to better protect them against attacks targeting the Windows kernel. The feature, which requires Virtualization-based Security (VBS) to be enabled, improves Windows security by only allowing trusted kernel-mode code and drivers to run on Windows 11 PCs.

Memory integrity is turned on by default on all Secured-core PCs. It’s also enabled by default after performing a clean install of Windows 11 on PCs. However, some PC manufacturers may choose to disable the feature, and IT admins can also disable it using Windows security and management tools.

“Beginning in October 2026, Microsoft will expand memory integrity protection across eligible devices, helping you and your organization benefit from stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration,” Microsoft explained yesterday. “To help ensure a reliable device experience, Windows automatically evaluates readiness before enabling memory integrity. Readiness signals include hardware capabilities, compatibility, and performance considerations.”

The bit about “performance considerations” is important because the feature can actually impact performance on PCs with older CPUs. Microsoft also acknowledged on a support page that “some applications and hardware device drivers may be incompatible with memory integrity.”

“Memory integrity works better with Intel Kabylake and higher processors with Mode-Based Execution Control, and AMD Zen 2 and higher processors with Guest Mode Execute Trap capabilities. Older processors rely on an emulation of these features, called Restricted User Mode, and will have a bigger impact on performance,” the company explained.

While most users should benefit from the expanded rollout of memory integrity protection, Microsoft is well inspired to proceed carefully. The feature also won’t be automatically enabled on PCs where it had already been disabled by users or IT admins.

Tagged with

Share post

Thurrott