Particle.news

Microsoft to Auto‑Enable Memory Integrity on Eligible Windows 11 PCs

The change strengthens kernel‑level defenses by using virtualization to block untrusted drivers before they run.

Overview

  • In a September 1 blog post Microsoft said quality updates starting in October 2026 will begin enabling Memory Integrity on eligible Windows 11 devices after a device readiness check.
  • Windows will run hardware, driver compatibility, and performance checks before turning the feature on and will not change machines where administrators or users have already disabled Memory Integrity.
  • Memory Integrity uses Virtualization‑based Security to isolate kernel‑mode code integrity checks so only trusted kernel drivers can execute, which helps stop attacks that try to compromise the Windows kernel.
  • The feature can cause reduced game frame rates on older CPUs, block incompatible kernel drivers, and disable undervolting tools that require virtualization to be off, so some users may need driver updates or to opt out temporarily.
  • Admins can control rollout at scale with Group Policy, Intune, or the registry and should consult CodeIntegrity event logs such as Event ID 3087 to diagnose blocked drivers while noting that Memory Integrity enables future servicing features like hotpatching.