News report

Windows 11 Starts Expanding Memory Integrity Protection in October

Microsoft is expanding Windows 11 Memory Integrity to more eligible PCs through October quality updates, while preserving deliberate opt-outs.

On this page
  1. Windows quality updates will enable Memory Integrity on more PCs
  2. Memory Integrity isolates kernel code-integrity checks
  3. Driver compatibility remains the practical risk
  4. Older compatible processors can carry a larger performance cost
  5. What Windows 11 users should watch during the rollout

Windows quality updates will enable Memory Integrity on more PCs

Microsoft says Windows quality updates beginning in October 2026 will start enabling Memory Integrity on more eligible Windows devices. On some systems, the change will also enable the underlying Virtualization-based Security (VBS) platform.

The rollout is gradual rather than a single universal switch. Microsoft says Windows evaluates device readiness before enablement using hardware capabilities, compatibility, performance considerations, Windows 11 requirements and recommended built-in protections.

Memory Integrity isolates kernel code-integrity checks

Memory Integrity is also known as Hypervisor-protected Code Integrity, or HVCI. It uses VBS and the Windows hypervisor to place kernel-mode code-integrity enforcement inside an isolated environment, making it harder for malware that compromises the normal Windows kernel to tamper with those checks.

Microsoft's documentation says the feature also restricts kernel memory allocations and only allows trusted kernel-mode code and drivers to run. That is why expanding it to existing eligible PCs is a meaningful security change rather than simply another Windows Security notification.

Driver compatibility remains the practical risk

The main compatibility boundary is kernel-mode software. Microsoft warns that some applications and hardware drivers remain incompatible with Memory Integrity and can malfunction after it is enabled; rare cases can result in a boot failure or blue screen.

Microsoft specifically lists gaming anti-cheat software, third-party input methods and third-party banking password protection among areas where incompatibilities have been observed. For a boot-critical incompatible driver, Windows can silently turn off Memory Integrity when it had been auto-enabled rather than leave the machine unable to boot.

Microsoft's documented hardware floor for automatic Memory Integrity enablement
AreaDocumented requirementWhy it matters
CPUIntel 8th Gen or later on Windows 11 22H2+, AMD Zen 2 or newer, or Snapdragon 8180 or newerNewer CPUs provide hardware features that reduce the cost of HVCI
MemoryAt least 8GB RAM on x64 systemsPart of Microsoft's automatic-enablement eligibility
StorageSSD of at least 64GBRequired by Microsoft's automatic-enablement logic
DriversMemory Integrity-compatible driversIncompatible kernel drivers can block or disrupt enablement
FirmwareVirtualization enabledVBS depends on hardware virtualization

Older compatible processors can carry a larger performance cost

Microsoft says Memory Integrity works better with Intel Kaby Lake and newer processors using Mode-Based Execution Control and with AMD Zen 2 and newer processors using Guest Mode Execute Trap. Older processors can fall back to Restricted User Mode emulation, which Microsoft says has a larger performance impact.

That does not establish a fixed gaming-performance penalty for every PC. The actual effect depends on the processor, workload, virtualization path and software stack, and Microsoft's October rollout includes performance considerations in its readiness assessment.

What Windows 11 users should watch during the rollout

Users can check the current state under Windows Security > Device security > Core isolation details > Memory integrity. If a previously working peripheral or low-level application stops behaving normally after the setting becomes enabled, Microsoft's supported first step is to look for a compatible driver or application update rather than immediately disabling the protection.

The useful boundary for October is therefore narrow: Microsoft is broadening default protection across eligible existing devices, but it is doing so gradually, checking readiness first and respecting deliberate prior configuration. Microsoft has not said that every eligible Windows 11 PC will switch on at the same time.

Sources

Primary and technical sources

These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.

  1. 01 Microsoft

    Windows message center — Expanding memory integrity protection across Windows devices
  2. 02 Microsoft Learn

    Enable virtualization-based protection of code integrity
  3. 03 Microsoft Learn

    Driver Compatibility with Hypervisor-Protected Code Integrity (HVCI)
  4. 04 Microsoft Learn

    Memory integrity enablement

Related

Technical guide

How to Back Up Installed Drivers in Windows 11

Export third-party driver packages from the Windows 11 driver store with PnPUtil, preserve them before a reinstall, and understand what the backup does and does not contain.