Windows 11: Memory Integrity enabled automatically from October

Microsoft is poised to enhance the security framework of Windows 11, with plans to automatically activate Memory Integrity on a broader range of eligible systems starting October 2026. This initiative will be rolled out through standard Windows quality updates, marking a shift from its previous limitation to new installations or specially configured PCs. Prior to activation, Windows will conduct a thorough assessment of the hardware, drivers, and overall performance profile of each system to ensure compatibility.

Understanding Memory Integrity and VBS

Memory Integrity, also known as Hypervisor-Protected Code Integrity (HVCI), is a critical component of Virtualization-based Security (VBS). This technology utilizes the Windows hypervisor to create a secure environment that is isolated from the main operating system. Within this safeguarded space, HVCI conducts integrity checks on kernel code, effectively thwarting malware attempts to manipulate essential security mechanisms after compromising the kernel.

An essential aspect of this technology is its stringent requirements regarding memory management. Executable kernel memory pages must pass integrity checks and cannot be writable simultaneously. This means that any techniques employed by drivers that dynamically alter code or treat memory as both writable and executable may conflict with HVCI’s protocols.

While Memory Integrity has been a feature of Windows for several years, it has been enabled by default only on compatible new installations of Windows 11. With this upcoming rollout, Microsoft aims to expand the pool of systems eligible for this feature through regular updates. Compatibility with drivers is a key prerequisite for this transition. Although HVCI compatibility has been a requirement for drivers since Windows 10 Version 1607, many older applications and device drivers still exist that may not meet these stricter standards.

Potential Compatibility Issues

Microsoft has identified several areas where compatibility issues may arise, including anti-cheat solutions, third-party input methods, and certain banking protection programs. The implications of these incompatibilities can range from software or hardware malfunctions to, in rare instances, boot failures. In cases where a critical boot driver is found to be incompatible, Windows will automatically deactivate the newly enabled Memory Integrity to prevent the system from becoming unbootable.

Users with older hardware are encouraged to review their systems closely. Devices such as printers, audio interfaces, RGB controllers, and monitoring tools may have drivers that have not been updated for years. While the hardware itself may be functioning well, the associated kernel drivers could be outdated, lacking the necessary HVCI compatibility.

Readiness Checks and System Requirements

Microsoft assures users that a readiness check will be conducted prior to activation. This check will evaluate not only the hardware but also compatibility and performance metrics. The current documentation specifies that Intel processors from the 8th generation onward, AMD processors from Zen 2 onward, and Qualcomm Snapdragon 8180 or newer are eligible for automatic activation. Additionally, x64 systems must have at least 8 GB of RAM, an SSD with a minimum capacity of 64 GB, enabled hardware virtualization, and compatible drivers.

While these technical specifications provide a framework, they do not guarantee that every system meeting these criteria will be transitioned immediately in October. Microsoft has indicated that the rollout will be gradual, contingent upon further compatibility and performance data. Users who have previously disabled HVCI will not face unexpected reactivation, as Microsoft has committed to respecting existing user and administrator decisions, along with configured policies.

Recommendations for Users

In the event of compatibility issues, Microsoft advises users to first attempt updating the affected application or driver before considering the deactivation of Memory Integrity. This approach is sensible, as HVCI is designed to prevent insecurely programmed or easily manipulable kernel components from accessing privileged memory areas.

The automatic activation of Memory Integrity is a logical step in bolstering security against kernel attacks, which are among the most challenging threats to address. However, the potential for older hardware to face functionality issues due to outdated drivers is a valid concern. Microsoft appears to be taking this risk seriously by implementing comprehensive compatibility checks ahead of the rollout. Users of specialized hardware, older peripherals, or unique kernel tools should remain vigilant, as a driver that suddenly fails to load may not be defective; it may simply no longer comply with HVCI standards.

Winsage
Windows 11: Memory Integrity enabled automatically from October