Windows 11 Memory Integrity Automatically Enabled in October
Starting in October 2026, Windows 11 quality updates will begin automatically switching on Memory Integrity, a kernel-level security feature, on PCs that qualify. Microsoft detailed the plan in a Windows IT Pro Blog post earlier this week, according to BetaNews, and confirmed the rollout arrives through the standard monthly quality-update channel rather than a feature-version upgrade, so no OS reinstall is required, per The Verge and BetaNews two days ago.
The change targets Windows 11 systems that were upgraded from earlier Windows versions or shipped with the feature off. Memory Integrity already runs by default on clean Windows 11 installs and Secured-core PCs, per BetaNews. Anyone who already disabled the feature manually, through Group Policy, or via Intune keeps that setting once the rollout begins. Readers can check where they currently stand right now by searching "Core Isolation" in Windows search and opening the Memory Integrity toggle under Device Security in the Windows Security app, per The Verge and BetaNews.
Windows 11 Memory Integrity rollout: which PCs are eligible
Eligibility documentation cited by Igor'sLAB yesterday lists minimum processor requirements for automatic activation:
- Intel 8th-generation or newer
- AMD Zen 2 or newer
- Qualcomm Snapdragon 8180 or newer
On x64 systems, Microsoft also requires at least 8GB of RAM, a 64GB or larger SSD, hardware virtualization enabled in firmware, and compatible drivers, according to Igor'sLAB.
Meeting those minimums doesn't guarantee automatic activation. Windows runs a device-level readiness check that weighs hardware, driver compatibility, and performance profile before switching Memory Integrity on, per Igor'sLAB. That check is what determines the outcome, more on it below.
IT-managed fleets get the same quality update automatically unless an existing administrator policy already overrides it, according to BetaNews's reporting on Microsoft's statement.
What Memory Integrity (HVCI) actually protects against
Memory Integrity, also called Hypervisor-protected Code Integrity or HVCI, runs on top of Virtualization-based Security (VBS), which uses the Windows hypervisor to wall off a protected memory space from the rest of the OS, per BetaNews and Igor'sLAB.
Inside that isolated space, HVCI checks kernel-mode code and drivers against a list of trusted software before letting them run. Code that fails the check cannot load directly into kernel memory, per BetaNews.
If VBS isn't already active on an eligible PC, the same October update is expected to turn it on too. Microsoft group program manager Peter Waxman described the move as part of making Windows "secure by design and secure by default," per The Verge.
Memory Integrity works alongside Microsoft's existing vulnerable-driver blocklist, a separate Windows Defender Application Control policy that already stops specific known-bad drivers from loading into the kernel. Both features check the same kernel entry point: the blocklist targets named drivers with known flaws, while HVCI validates kernel-mode code more broadly against a trusted list, per BetaNews. No setup is required to benefit once it's active; it runs quietly in the background.
Memory Integrity incompatible drivers: what could break before October
Before switching the feature on, Windows runs that readiness check across hardware, driver compatibility, and performance profile, intended to avoid enabling HVCI on systems with known technical drawbacks, per Igor'sLAB. The check runs per device, so passing the general hardware minimums above doesn't guarantee a pass here.
Microsoft's own documentation, as reported by Igor'sLAB, names anti-cheat software, third-party input tools, and certain banking-protection programs as categories where compatibility problems have already surfaced.
One user ran into this firsthand on Windows 10: a post on Microsoft Community Hub roughly three months ago described being unable to enable Memory Integrity because of an incompatible Sonix camera driver, snUVC.sys. That's one report, not proof of a widespread issue, but it shows exactly how a driver conflict surfaces in the wild.
Kernel-level driver enforcement has broken real applications before. Microsoft's April 2026 security updates blocked a separate vulnerable driver, psmounterex.sys, which caused some backup software to fail when mounting disk images, according to Microsoft Support. That incident came from the unrelated vulnerable-driver blocklist, not HVCI, but it's a reminder that this category of hardening has real-world side effects.
If Windows detects an incompatible boot-critical driver after automatic activation, it's designed to silently disable Memory Integrity again rather than leave a system unable to start, per Igor'sLAB. If the feature fails to activate, or an app breaks afterward, Microsoft's guidance, per Igor'sLAB, is to update the affected driver or application first, before turning the feature back off.
Gaming performance and how to check or disable Windows 11 Memory Integrity
Microsoft has previously acknowledged that Memory Integrity can affect gaming performance, with more noticeable frame-rate drops in select games on older processors within the eligible range, per The Verge.
Current-generation CPUs with native hardware virtualization support should see little change. CPUs closer to the minimum eligibility threshold, which lean more on software-assisted checks, may show lower or less consistent frame rates, per BetaNews. Neither outlet has published actual benchmark numbers, so treat those descriptions as qualitative for now rather than a guaranteed hit.
Checking or disabling the feature takes seconds. Search "Core Isolation" in Windows search, open the result, and toggle Memory Integrity under Device Security in the Windows Security app; no registry edits or command-line tools are needed, per The Verge and BetaNews. That toggle only shows the feature's current status. It doesn't confirm whether a device will pass October's automatic-activation readiness check.
Microsoft's own recommendation for performance-sensitive gamers is to disable Memory Integrity before a session and turn it back on afterward, rather than leaving it off permanently, per The Verge.
What to check before October
Open Windows Security today and look at the Core Isolation setting to see where things stand. If it's already on, there's nothing to do. If it's off because someone turned it off deliberately, reporting indicates Microsoft will leave that alone. If it's off and no one has ever touched it, expect it to be a likely candidate for October's update, pending Windows' own compatibility check on that specific device.
Anyone relying on banking-security software, anti-cheat systems, or older peripheral drivers should update those tools now rather than wait to troubleshoot a failure once the update lands.
Comments
Be the first, drop a comment!