Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCs
The change will make VBS-based kernel checks the security baseline to block untrusted drivers and reduce the risk of kernel-level attacks.
Overview
- Microsoft announced in early September 2026 that Windows quality updates will begin turning on Memory Integrity by default for eligible Windows 11 devices starting in October 2026.
- Memory Integrity is Hypervisor‑protected Code Integrity built on Virtualization‑based Security that checks kernel‑mode drivers in an isolated environment and blocks untrusted code from running.
- Before enabling the feature, Windows will run automated readiness checks for hardware, drivers, and performance and will not change devices where admins or users have already disabled Memory Integrity.
- Incompatible or legacy drivers remain the main operational risk and are logged under CodeIntegrity in Event Viewer with Event ID 3087, and such conflicts have in some cases caused boot failures on older machines.
- Microsoft and reporters warn the feature can reduce gaming frame rates on some systems, and enterprises are advised to manage rollout via Group Policy, Intune, or registry settings while they seek driver updates from OEMs.