Microsoft Will Start Turning On Memory Integrity Automatically on Windows 11 PCs


secure boots expering windows 11
Image credit: Microsoft

Microsoft will begin enabling Memory Integrity by default on eligible Windows 11 PCs with the October 13, 2026 Patch Tuesday update.

The change targets compatible systems where the security feature remains disabled, particularly PCs upgraded from older Windows versions. Windows will run a readiness assessment before switching it on.

Microsoft is expanding HVCI protection

Memory Integrity, also known as Hypervisor-Protected Code Integrity or HVCI, helps protect Windows against attacks targeting the kernel.

Microsoft wants to enable the existing protection across more compatible Windows 11 devices instead of limiting it mostly to newer systems where manufacturers already turned it on.

The October rollout will focus on eligible PCs that meet Microsoft’s hardware and driver requirements but still have Memory Integrity disabled.

How Memory Integrity protects Windows 11

Memory Integrity works with Virtualization-based Security, or VBS, to isolate sensitive parts of Windows from the rest of the operating system.

It uses hardware virtualization features in the processor to create an isolated environment where Windows can verify kernel-mode code before allowing it to run.

Drivers must pass integrity checks before Windows permits them to execute. This can help stop unsigned, malicious, or vulnerable drivers from compromising the Windows kernel.

Which Windows 11 PCs are eligible

Microsoft will only enable Memory Integrity automatically on devices that pass its readiness checks.

Eligible systems generally need:

  • Intel 8th-generation processors or newer.
  • AMD Zen 2 processors or newer.
  • Qualcomm Snapdragon 8180 processors or newer.
  • Virtualization enabled in firmware.
  • Drivers that already support Memory Integrity.

Secured-core PCs generally already ship with Memory Integrity enabled, so the upcoming change mainly affects other compatible systems.

Microsoft will respect existing Memory Integrity opt-outs

Microsoft says Windows will not automatically turn Memory Integrity back on when administrators or users have deliberately disabled it.

Existing configurations that disable the feature through Group Policy, Intune, or the Windows Registry will remain in place.

This means organizations that disabled Memory Integrity because of compatibility requirements should not see Windows override those settings during the October rollout.

Older drivers could still cause compatibility problems

Driver compatibility remains one of the main reasons Microsoft has not enabled Memory Integrity universally across Windows 11.

Some older drivers perform memory operations that Memory Integrity does not allow. Windows can block those drivers from loading once the protection becomes active.

In previous cases, incompatible drivers have also caused hardware problems or boot-related issues. Microsoft’s readiness assessment should help identify affected systems before enabling the feature.

In other news, Microsoft is changing Windows Update so your PC can restart fewer times when installing updates.

Meanwhile, thousands of Exchange Servers remain vulnerable to a recently patched security flaw.

Via Windows Latest

More about the topics: microsoft, Windows 11

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages