Microsoft will start mechanically enabling its Memory Integrity safety characteristic on a broader vary of eligible Windows PCs by high quality updates beginning in October 2026, extending the kernel-level safety to extra present units by default. In a September 1 weblog publish, Microsoft mentioned the rollout will present stronger safety for extra units in opposition to assaults concentrating on the Windows kernel, whereas PCs that have already got Memory Integrity intentionally disabled will retain their present configuration.
“Windows quality updates will begin enabling memory integrity protection on eligible devices,” Microsoft mentioned. The updates may also allow Virtualization-based Security (VBS) the place required, which gives the remoted setting underlying Memory Integrity. Before making the change, Windows will mechanically assess every gadget utilizing what Microsoft describes as readiness indicators masking its {hardware} capabilities, compatibility, and efficiency.
The October rollout is mainly an growth of Microsoft’s present default-enablement coverage. Memory Integrity is already switched on by default on clear Windows 11 installations that meet Microsoft’s hardware requirements, as well as on Secured-core PCs. Current requirements include an 8th Gen or newer Intel processor for Windows 11 22H2, an AMD Zen 2 or newer processor, at least 8GB of RAM on x64 systems, an SSD of at least 64GB, compatible drivers, and enabled hardware virtualization. Automatic activation under that policy applies to clean installations and not upgrades of existing devices.
Latest Videos FromTom’s Hardware
Memory Integrity — also known as Hypervisor-Protected Code Integrity (HVCI) — has existed since the Windows 10 era and was originally released as part of Microsoft’s Device Guard security technology. It uses VBS and the Windows hypervisor to move kernel-mode code-integrity checks into an isolated environment, helping prevent malicious or untrusted code and drivers from executing in the Windows kernel. Windows 10 generally left the protection optional outside configurations such as S mode, while Windows 11 made it more of a default security feature on compatible new installations.
The feature comes with a performance wrinkle familiar to PC gamers, leading many gamers to disable it. Microsoft acknowledged in 2022 that Memory Integrity and Virtual Machine Platform could affect gaming performance on some Windows 11 configurations, and advised gamers prioritizing performance that they could temporarily disable these protections while playing, warning that doing so reduces security. The company’s own gaming guidance subsequently continued to recommend temporarily disabling Memory Integrity and VMP where they interfere with gaming performance.
The security feature’s impact on performance depends on the hardware. Microsoft says Memory Integrity performs better on newer processors with hardware features designed to accelerate the required isolation, while older CPUs relying on software emulation can experience a larger performance hit. Driver compatibility can also prevent activation, with Microsoft documenting issues ranging from malfunctioning software to incompatible gaming anti-cheat solutions.
For most users, the October change requires no action. Eligible PCs will be evaluated and updated automatically, while administrator policies and previous user choices remain in place. Microsoft specifically says systems where Memory Integrity has already been disabled “won’t be automatically changed by this rollout,” leaving gamers and other users who previously opted out in control of the setting.
Follow Tom’s Hardware on Google News, or add us as a preferred source, to get our newest information, evaluation, & evaluations in your feeds.