Microsoft Expands Windows 11 Memory Integrity to More PCs in October
Microsoft plans to automatically enable Memory Integrity on a broader range of Windows 11 PCs starting in October 2026, extending kernel-level security protections to more existing devices by default while preserving the settings of users who have deliberately disabled the feature.
In a September 1 blog post, Microsoft announced that Windows quality updates will begin enabling memory integrity protection on eligible devices. The rollout will also enable Virtualization-based Security (VBS) where required, as VBS provides the isolated environment underlying Memory Integrity. Before making the change, Windows will automatically assess each device using what Microsoft describes as readiness signals covering its hardware capabilities, compatibility, and performance.
The October rollout is an expansion of Microsoft’s existing default-enablement policy. Memory Integrity is already switched on by default on clean Windows 11 installations that meet Microsoft’s hardware requirements, as well as on Secured-core PCs. Current requirements include an 8th Gen or newer Intel processor for Windows 11 22H2, an AMD Zen 2 or newer processor, at least 8GB of RAM on x64 systems, an SSD of at least 64GB, compatible drivers, and enabled hardware virtualization. Automatic activation under that policy applies to clean installations and not upgrades of existing devices.
Memory Integrity, also known as Hypervisor-Protected Code Integrity (HVCI), has existed since the Windows 10 era and was originally released as part of Microsoft’s Device Guard security technology. It uses VBS and the Windows hypervisor to move kernel-mode code-integrity checks into an isolated environment, helping prevent malicious code from executing in kernel space. This protection helps defend against attacks targeting the Windows kernel, which can be particularly dangerous because kernel-level code has full access to system resources.
Microsoft stated that the rollout will provide stronger protection for more devices against attacks targeting the Windows kernel. However, the company also acknowledged that Memory Integrity can reduce gaming performance on some systems. The performance impact varies depending on the specific hardware configuration and the games being played, with some users reporting noticeable frame rate drops in certain titles.
PCs that already have Memory Integrity deliberately disabled will retain their existing configuration. This means users who have manually turned off the feature for performance reasons will not have it re-enabled by the October updates. However, Microsoft’s statement that these PCs will retain their configuration is specific to the current rollout and does not guarantee that future updates will not change this policy.
The expansion of Memory Integrity to more PCs represents a significant shift in how Microsoft approaches default security settings. By moving from a model where the feature is enabled only on clean installations to one where it is enabled on a broader range of existing devices, Microsoft is prioritizing security over performance for a larger user base. This approach aligns with the company’s broader strategy of making security features more accessible and less dependent on user configuration.
Users who are concerned about the potential performance impact should monitor their system’s behavior after the October updates are released. If they experience significant performance degradation in games or other applications, they can consider disabling Memory Integrity, though this will reduce their system’s security posture. The decision to enable or disable the feature ultimately depends on the user’s priorities regarding security versus performance.
Microsoft’s decision to expand Memory Integrity to more PCs is part of a broader trend in the industry toward more secure default configurations. As cyber threats become more sophisticated, operating system vendors are increasingly prioritizing security features that protect against advanced attacks. While this can sometimes come at the cost of performance, the trade-off is often considered worthwhile given the potential consequences of a successful kernel-level attack.
The October 2026 rollout will be delivered through Windows quality updates, meaning users will receive the changes as part of their regular update cycle. There is no separate action required for users to opt in, as the feature will be enabled automatically on eligible devices. Users who want to verify whether their system is eligible can check their system specifications against Microsoft’s requirements or monitor their Windows Update history for the relevant quality update.
Microsoft’s approach to Memory Integrity reflects a balance between security and usability. By enabling the feature by default on a broader range of devices, the company is ensuring that more users benefit from kernel-level protection without having to manually configure security settings. At the same time, by allowing users to disable the feature if needed, Microsoft is acknowledging that performance considerations may be important for some users, particularly gamers and power users who rely on their systems for demanding tasks.
The expansion of Memory Integrity to more PCs is a significant development for the Windows ecosystem. It represents a shift toward more secure default configurations and a recognition that kernel-level protection is essential for defending against modern cyber threats. While the potential performance impact is a concern for some users, the security benefits of Memory Integrity are substantial, and the feature is likely to become an increasingly important part of the Windows security landscape.
As Microsoft continues to evolve its security offerings, users should stay informed about the changes being made to their systems and make decisions about security features based on their own needs and priorities. The October 2026 rollout of Memory Integrity is a step in the right direction for improving the security of Windows 11, and it is likely to have a positive impact on the overall security posture of the Windows ecosystem.