Microsoft is auto-enabling Memory Integrity on Windows 11 PCs from October. Why you shouldn’t turn it off

Starting in October 2026, Microsoft will automatically activate memory integrity for eligible Windows 11 devices. This significant update will roll out through the Patch Tuesday update on October 13, marking a pivotal moment in enhancing security for users without requiring manual adjustments.

What is Memory Integrity and why does Microsoft want it enabled?

Memory integrity, also known as Hypervisor-protected Code Integrity (HVCI), operates alongside Virtualization-based Security. It leverages the CPU’s virtualization capabilities to create an isolated environment, safeguarding the core of Windows from direct access. This means that kernel-mode drivers, which are essential for the operating system’s functionality, must pass through this isolated checker before execution. Consequently, any malware attempting to infiltrate via a vulnerable or unsigned driver is thwarted at this critical juncture.

Memory Integrity turned on in Windows Security. Credit: Windows Latest

Which PCs get Memory Integrity automatically enabled in October?

While not every Windows 11 PC will benefit from this automatic enablement, Microsoft has set relatively lenient hardware requirements:

  • Intel 8th-generation processor or newer,
  • AMD Zen 2 or newer,
  • Qualcomm Snapdragon 8180 or newer,
  • at least 8GB of RAM on x64 systems,
  • a 64GB SSD, with virtualization enabled in firmware,
  • and drivers that are already confirmed compatible with memory integrity.

Secured-core PCs, which meet a certification standard set by Microsoft and OEMs for business and enterprise hardware, currently come with this feature enabled. To ensure a smooth transition, Windows will conduct a readiness assessment on each device prior to activation, rather than applying the change indiscriminately to all qualifying PCs. If a device has intentionally disabled memory integrity—whether through Group Policy, Intune, or manual registry alterations—Windows Update will respect that setting, allowing for an opt-out approach rather than a forced implementation.

  • To check if memory integrity is active, navigate to Windows Security > Device security > Core isolation.
  • The status of the Memory integrity toggle will be displayed directly on that page.
  • IT administrators can pre-configure the feature using registry keys under HKLMSystemCurrentControlSetControlDeviceGuardScenariosHypervisorEnforcedCodeIntegrity, or manage it at scale through Group Policy and Intune.

Incompatible drivers have been a primary reason for the feature’s limited activation thus far. Older drivers that interact with memory in ways that memory integrity does not permit may be blocked from loading, potentially leading to boot failures on legacy hardware. Windows logs these conflicts in the Event Viewer under Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational, tagged with Event ID 3087 when a driver is identified as incompatible. Users experiencing issues after the rollout should consult this log first.

Why Microsoft is pushing this now

Recent pressures on Windows security have prompted Microsoft to take decisive action. The rise of AI-assisted vulnerability research has accelerated the discovery of kernel-level bugs, making it imperative for the company to bolster defenses swiftly. Enabling a feature that has remained dormant on millions of eligible PCs presents an efficient means to mitigate a broad category of attacks without waiting for more extensive fixes throughout the operating system.

Core isolation in Windows Security. Credit: Windows Latest

Memory integrity was not exclusive to Windows 11; it was introduced as an opt-in feature in Windows 10 and became the default for clean installations on compatible hardware. However, many users have upgraded their systems over the years rather than performing clean installs, which is the demographic Microsoft aims to reach with this upcoming update. These devices have always met the hardware qualifications but have had the protection disabled.

Should you turn Memory Integrity off? Usually, no

If your PC has memory integrity activated and experiences issues—typically due to an older driver failing to load—Windows Security will flag the problem under Core isolation, identifying the responsible driver in the CodeIntegrity event log. In such cases, users can either wait for an updated driver from the manufacturer or disable the feature temporarily, a trade-off that those with memory integrity already enabled have navigated for years.

Winsage
Microsoft is auto-enabling Memory Integrity on Windows 11 PCs from October. Why you shouldn't turn it off