Microsoft Will Start Turning On Memory Integrity Automatically on Windows 11 PCs
Microsoft will begin enabling Memory Integrity by default on eligible Windows 11 PCs with the October 13, 2026 Patch Tuesday update.
The change targets compatible systems where the security feature remains disabled, particularly PCs upgraded from older Windows versions. Windows will run a readiness assessment before switching it on.
Microsoft is expanding HVCI protection
Memory Integrity, also known as Hypervisor-Protected Code Integrity or HVCI, helps protect Windows against attacks targeting the kernel.
Microsoft wants to enable the existing protection across more compatible Windows 11 devices instead of limiting it mostly to newer systems where manufacturers already turned it on.
The October rollout will focus on eligible PCs that meet Microsoft’s hardware and driver requirements but still have Memory Integrity disabled.
How Memory Integrity protects Windows 11
Memory Integrity works with Virtualization-based Security, or VBS, to isolate sensitive parts of Windows from the rest of the operating system.
It uses hardware virtualization features in the processor to create an isolated environment where Windows can verify kernel-mode code before allowing it to run.
Drivers must pass integrity checks before Windows permits them to execute. This can help stop unsigned, malicious, or vulnerable drivers from compromising the Windows kernel.
Which Windows 11 PCs are eligible
Microsoft will only enable Memory Integrity automatically on devices that pass its readiness checks.
Eligible systems generally need:
- Intel 8th-generation processors or newer.
- AMD Zen 2 processors or newer.
- Qualcomm Snapdragon 8180 processors or newer.
- Virtualization enabled in firmware.
- Drivers that already support Memory Integrity.
Secured-core PCs generally already ship with Memory Integrity enabled, so the upcoming change mainly affects other compatible systems.
Microsoft will respect existing Memory Integrity opt-outs
Microsoft says Windows will not automatically turn Memory Integrity back on when administrators or users have deliberately disabled it.
Existing configurations that disable the feature through Group Policy, Intune, or the Windows Registry will remain in place.
This means organizations that disabled Memory Integrity because of compatibility requirements should not see Windows override those settings during the October rollout.
Older drivers could still cause compatibility problems
Driver compatibility remains one of the main reasons Microsoft has not enabled Memory Integrity universally across Windows 11.
Some older drivers perform memory operations that Memory Integrity does not allow. Windows can block those drivers from loading once the protection becomes active.
In previous cases, incompatible drivers have also caused hardware problems or boot-related issues. Microsoft’s readiness assessment should help identify affected systems before enabling the feature.
In other news, Microsoft is changing Windows Update so your PC can restart fewer times when installing updates.
Meanwhile, thousands of Exchange Servers remain vulnerable to a recently patched security flaw.
Via Windows Latest
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages