Microsoft will expand Windows 11 Memory Integrity feature to more PCs starting in October — security feature reduces gaming performance on some systems

Windows 11
(Image credit: Microsoft)

Microsoft will begin automatically enabling its Memory Integrity security feature on a broader range of eligible Windows PCs through quality updates starting in October 2026, extending the kernel-level protection to more existing devices by default. In a September 1 blog post, Microsoft said the rollout will provide stronger protection for more devices against attacks targeting the Windows kernel, while PCs that already have Memory Integrity deliberately disabled will retain their existing configuration.

“Windows quality updates will begin enabling memory integrity protection on eligible devices,” Microsoft said. The updates will also enable Virtualization-based Security (VBS) where required, which provides the isolated environment underlying Memory Integrity. Before making the change, Windows will automatically assess each device using what Microsoft describes as readiness signals covering its hardware capabilities, compatibility, and performance.

The October rollout is basically an expansion of Microsoft’s existing default-enablement policy. Memory Integrity is already switched on by default on clean Windows 11 installations that meet Microsoft’s hardware requirements, as well as on Secured-core PCs. Current requirements include an 8th Gen or newer Intel processor for Windows 11 22H2, an AMD Zen 2 or newer processor, at least 8GB of RAM on x64 systems, an SSD of at least 64GB, compatible drivers, and enabled hardware virtualization. Automatic activation under that policy applies to clean installations and not upgrades of existing devices.

Latest Videos FromTom's Hardware

Memory Integrity — also known as Hypervisor-Protected Code Integrity (HVCI) — has existed since the Windows 10 era and was originally released as part of Microsoft’s Device Guard security technology. It uses VBS and the Windows hypervisor to move kernel-mode code-integrity checks into an isolated environment, helping prevent malicious or untrusted code and drivers from executing in the Windows kernel. Windows 10 generally left the protection optional outside configurations such as S mode, while Windows 11 made it more of a default security feature on compatible new installations.

The feature comes with a performance wrinkle familiar to PC gamers, leading many gamers to disable it. Microsoft acknowledged in 2022 that Memory Integrity and Virtual Machine Platform could affect gaming performance on some Windows 11 configurations, and advised gamers prioritizing performance that they could temporarily disable these protections while playing, warning that doing so reduces security. The company’s own gaming guidance subsequently continued to recommend temporarily disabling Memory Integrity and VMP where they interfere with gaming performance.

The security feature’s impact on performance depends on the hardware. Microsoft says Memory Integrity performs better on newer processors with hardware features designed to accelerate the required isolation, while older CPUs relying on software emulation can experience a larger performance hit. Driver compatibility can also prevent activation, with Microsoft documenting issues ranging from malfunctioning software to incompatible gaming anti-cheat solutions.

For most users, the October change requires no action. Eligible PCs will be evaluated and updated automatically, while administrator policies and previous user choices remain in place. Microsoft specifically says systems where Memory Integrity has already been disabled “won’t be automatically changed by this rollout,” leaving gamers and other users who previously opted out in control of the setting.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Etiido Uko
News Contributor

Etiido Uko is a news contributor for Tom's Hardware covering the latest updates in big tech and the PC industry. He is a mechanical engineer and senior technical writer with over nine years of experience in documentation and reporting. He is deeply passionate about all things engineering and technology, and is an expert in gadgets, manufacturing, robotics, automotive, and aerospace.

  • ezst036
    Reduce gaming performance eh? *This is me looking at SteamOS*

    In other thoughts, I hope further integrity pushes lead to Microsoft kicking kernel level anti-cheat solutions to the curb.

    Less is more when it comes to true security of people's personal PII data.

    Admin said:
    PCs that already have Memory Integrity deliberately disabled will retain their existing configuration

    For now. But that statement has an expiration date. Microsoft has long since weaponized Windows Update in order to force people into Edge, Bing, start men advertisements, AI/Copilot junk nobody wants, and other settings people are setting but then later discovering, it was reverted back. Windows Update has become one of the most despised systems within the OS because of all this.

    Microsoft is a bully. Bullies are gonna bully. That's just what they do that's just what Microsoft is. A shark is a shark, a mosquito is a mosquito. They do the things you predict they are going to do. It is in their nature.
    Reply
  • LordVile
    ezst036 said:
    Reduce gaming performance eh? *This is me looking at SteamOS*

    In other thoughts, I hope further integrity pushes lead to Microsoft kicking kernel level anti-cheat solutions to the curb.

    Less is more when it comes to true security of people's personal PII data.



    For now. But that statement has an expiration date. Microsoft has long since weaponized Windows Update in order to force people into Edge, Bing, start men advertisements, AI/Copilot junk nobody wants, and other settings people are setting but then later discovering, it was reverted back. Windows Update has become one of the most despised systems within the OS because of all this.

    Microsoft is a bully. Bullies are gonna bully. That's just what they do that's just what Microsoft is. A shark is a shark, a mosquito is a mosquito. They do the things you predict they are going to do. It is in their nature.
    The “I don’t like kernel level anticheat” crowd are funny. Especially when they’re running 10 RGB softwares which all have ring 0 access
    Reply
  • USAFRet
    ezst036 said:
    Reduce gaming performance eh? *This is me looking at SteamOS*
    You know this is optional and can be turned off, right?

    And "Automatic activation under that policy applies to clean installations and not upgrades of existing devices."
    Reply
  • TechieTwo
    Apparently MS's Biz practices don't work well in the NBA. Ask Steve Ballmer. :(
    Reply
  • ezst036
    USAFRet said:
    You know this is optional and can be turned off, right?

    And "Automatic activation under that policy applies to clean installations and not upgrades of existing devices."
    For now. But knowing Microsoft that statement has an expiration date.
    Reply
  • USAFRet
    ezst036 said:
    For now. But knowing Microsoft that statement has an expiration date.
    Everything is a "for now" concept.

    "for now", this exists and is opt-outable.
    2 years from now, Microsoft might get rid of it completely. Or make it worse.
    Reply
  • wiscovitch
    Fallout from this that wasn't covered...Really messes with using anything other than Hyper-V virtualization.

    Meaning VirtualBox runs in green turtle mode...No bueno
    Reply
  • ezst036
    USAFRet said:
    Or make it worse.
    Knowing Microsoft.............

    🤔

    You know.
    Reply