This guide covers what Memory integrity is, what actually changed in October 2026, how to tell whether it is causing your problem, and how to turn it off safely if you really need to.
What changed this month
The backlash has a real cause. In a September 1 blog post, Microsoft said that it will begin automatically enabling its Memory Integrity security feature on a broader range of eligible Windows PCs through quality updates starting in October 2026, extending the kernel-level protection to more existing devices by default. Microsoft's own Message Center notice (MC1465669) says beginning in October 2026, Windows quality updates will start enabling memory integrity on more eligible Windows devices. On some devices, this change will also enable virtualization-based security (VBS).
This is a real policy change, and it matters because of what the old rules were. Microsoft's hardware documentation for Memory integrity, last updated October 28, 2025, says the feature was on by default for clean installs of Windows 11 on compatible hardware and on all Secured-core PCs. A note in that document says automatic enablement covered only clean installs, not upgrades of existing devices. The October rollout removes that limit. For the first time, PCs that are already in use can have the feature switched on by a normal monthly update.
The rollout is less forceful than the "Windows forces it on everyone" claims suggest:
- Your earlier choice is respected. According to Tom's Hardware's reading of the announcement, PCs that already have Memory Integrity deliberately disabled will retain their existing configuration.
- Managed fleets keep their policies. IT-managed PCs are included in the broader rollout, but existing Group Policy, Intune, administrator, and user choices remain in force.
- Each PC is checked first. Before enabling the protection, Windows evaluates device readiness based on hardware capabilities, compatibility, performance considerations, Windows 11 system requirements, and recommended built-in protections.
- The rollout is gradual. Microsoft says the gradual rollout begins in October 2026. It might not reach all eligible devices at the same time.
Summary: Microsoft really is enabling Memory integrity on existing PCs, which it did not do before. It checks each device first, and it does not override a setting you or your admin already turned off.
What Memory integrity actually does
Memory integrity is the user-facing name for Hypervisor-protected Code Integrity (HVCI). Microsoft's documentation describes it as a virtualization-based security feature available in Windows 10, Windows 11 and Windows Server 2016 or later. It started as part of Device Guard. That old name now survives mainly in Group Policy and registry paths.
The idea is straightforward. Normally, Windows checks whether kernel code is trustworthy using code that runs inside the kernel. If an attacker controls the kernel, that check can't be trusted either. VBS uses the Windows hypervisor to create a separate, isolated environment, and Memory integrity moves the kernel's code-integrity checks into it. Microsoft's documentation lists two key rules:
- Kernel memory pages become executable only after they pass code-integrity checks inside that protected environment.
- Executable pages can never also be writable.
The second rule blocks a common attack technique: writing code into memory and then running it. That matters because the kernel controls memory, hardware and security settings. As How-To Geek explains, malware running at kernel level could turn off your antivirus before launching ransomware. Code running as a normal app can't do that as easily.
This does not make a PC impossible to hack, and it does not replace antivirus. It makes one of the most damaging kinds of compromise much harder.
Vulnerable drivers: why gamers are affected on both sides
Gamers complain most about this feature, and they are also the people most exposed to the attack it targets. How-To Geek points to Bring Your Own Vulnerable Driver (BYOVD) attacks. In these, an attacker doesn't write a malicious driver. Instead, they install a legitimate, signed driver with a known flaw and use that flaw to reach the kernel.
WinRing0 is a clear example. Microsoft Defender detects it as VulnerableDriver:WinNT/Winring0. Microsoft's support page calls the detection valid and links the driver to CVE-2020-14979. Microsoft's list of possibly affected tools reads like a PC enthusiast's taskbar: CapFrameX, older versions of EVGA Precision X1, FanCtrl, HWiNFO, Libre Hardware Monitor, MSI Afterburner, Open Hardware Monitor, OpenRGB, OmenMon, Panorama9, SteelSeries Engine and ZenTimings.
Two details matter here. First, that list does not mean every version of every one of those apps is vulnerable. Check what your installed version actually loads. Second, Microsoft's page also describes adding a Defender exclusion to stop the alert, and Microsoft says it does not recommend that workaround because it can leave the PC more exposed. That is a separate decision from turning off Memory integrity, but the reasoning is the same: silencing a warning does not fix the underlying problem.
Compatibility and performance problems are real
Microsoft acknowledges the trade-offs in its own developer documentation. Drivers have been required to be compatible with Memory integrity since the Windows 10 Anniversary Update (1607), yet some apps and drivers still are not. That can make devices or software misbehave and, in rare cases, cause a blue screen at boot. Microsoft names two problem categories directly: anti-cheat software in games and third-party banking password protection.
Microsoft also includes a safety net. If a boot-critical driver is incompatible, Memory integrity is silently turned off when it was auto-enabled. That reduces the risk that an automatic update leaves a PC unable to boot.
Performance is harder to pin down. Running code-integrity checks inside a hypervisor adds work, and Tom's Hardware's coverage of the rollout says the feature reduces gaming performance on some systems. How-To Geek says lower-end PCs are most likely to notice. However, Microsoft's documentation offers no universal FPS penalty, and neither article provides benchmark data. Be wary of anyone who quotes one percentage for every system. The impact depends on the CPU generation, the game, the drivers and the workload.
How-To Geek also lists the hardware Microsoft uses for automatic enablement. Microsoft's documentation gives the details:
| Component | Minimum for automatic enablement |
|---|---|
| Processor | Intel 8th gen or later (Windows 11 22H2+); Intel 11th gen Core+ on 21H2; AMD Zen 2+; Qualcomm Snapdragon 8180+ |
| RAM | 8 GB (x64 only) |
| Storage | SSD, at least 64 GB |
| Drivers | Memory integrity–compatible drivers installed |
| Firmware | Virtualization enabled in BIOS/UEFI |
One exception is easy to miss. Intel 11th-generation Core desktop processors aren't included in its current default-enablement logic, although Microsoft still recommends the platform for Memory Integrity and OEMs can enable it. Meeting the minimums also doesn't guarantee anything, because meeting those requirements doesn't guarantee that October's update will switch the feature on.
Summary: Driver and anti-cheat conflicts are documented, and the performance cost depends on the system. Neither is a reason to turn the feature off before you know whether it affects you.
Step 1: Check whether Memory integrity is on
Microsoft documents several ways to check:
- Windows Security: Start > Settings > Privacy & security > Windows Security > Device security, then select Core isolation details under Core isolation. The Memory integrity toggle shows whether it's on.
- System Information: Run
msinfo32and find Virtualization-based security Services Running. If it lists Hypervisor enforced Code Integrity, the feature is active. - Registry (read-only check): The volatile value
HVCIEnabledunderHKLM\System\CurrentControlSet\Control\CI\Stateshows the current state.
Step 2: Confirm whether it's actually blocking anything
Before blaming the setting, look for evidence. Microsoft says to open Event Viewer and go to Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational. Memory integrity compatibility events usually have Event ID 3087. If a driver your device or app needs appears there, you've found the conflict. If nothing appears, your stutter or crash probably has another cause.
If Windows shows a "driver can't load on this device" notice, Microsoft's support page says the driver most likely has a minor vulnerability and is probably not malicious. The notification includes the driver name and company name. Use those to find the vendor.
Step 3: Fix the driver before reaching for the toggle
Microsoft recommends this order:
- Look for an updated, compatible driver in Windows Update or on the manufacturer's site.
- Update the app itself. For incompatible software, Microsoft advises checking for an update to that specific app and version before turning off the protection.
- Remove or replace old tools you don't need, such as stale monitoring or RGB utilities that load old kernel drivers.
- Contact the vendor if no fix exists. Microsoft suggests asking whether one is coming.
Step 4: If you must, turn it off and test properly
If the problem continues and costs you something important, you can turn it off. How-To Geek's path matches Microsoft's:
- Open Windows Security > Device security > Core isolation details.
- Switch Memory integrity to Off.
- Restart. The change doesn't take effect until you do.
Test fairly. Use the same game, the same scene and the same settings with the feature on and then off. Change nothing else. If you can't measure a difference, turn it back on.
Two warnings from Microsoft: turning off Memory integrity on a Secured-core PC takes the device out of its Secured-core state. And if you leave a driver problem unresolved, the hardware feature that driver supports may stop working. Microsoft says the consequences could range from "negligible to severe."
How-To Geek also suggests turning the feature off only while you play the affected game, then turning it back on. That works, but every switch requires a restart, so most people will only do it for a short while before giving up.
Turning it off doesn't remove every driver defense
Microsoft's vulnerable driver blocklist is a separate layer. Microsoft says that since the Windows 11 2022 Update, the blocklist is on by default for all devices and can be turned on or off in Windows Security. It's updated every quarter and also delivered through monthly updates. However, Microsoft also says the blocklist isn't guaranteed to cover every vulnerable driver, and that it sometimes delays adding blocks to avoid breaking working software. Microsoft's top recommendation is still HVCI or S mode, with the blocklist as a fallback when those aren't practical.
So turning off Memory integrity doesn't leave you with no protection, but it does leave you with less. How-To Geek's advice for people who do turn it off applies here: keep drivers updated, uninstall software you no longer use, and download only from reputable sources.
Advice for IT administrators
Admins have more to plan for than gamers. Your existing Intune and Group Policy settings stay in force, so a fleet you have already configured won't change unexpectedly. Unmanaged or loosely managed devices are different, because quality updates may enable both VBS and Memory integrity on them. Check which devices have older peripherals, banking-security plugins or specialist hardware with old drivers, and review CodeIntegrity Event ID 3087 entries now rather than waiting for helpdesk tickets.
For devices where HVCI really can't run, Microsoft recommends deploying its recommended driver block rules through an App Control for Business policy. Validate the policy in audit mode before you enforce it.
Bottom line
The complaints about the rollout have some basis. Microsoft is now enabling Memory integrity on existing PCs through monthly updates, and anti-cheat and driver conflicts are documented. But turning it off as a reflex, with no evidence, gives up real kernel protection based on rumors.
How-To Geek's conclusion is sound: if everything works and you can't measure a slowdown, leave it on. If a specific driver, game or device breaks, check the CodeIntegrity log, look for updates, and only then make a deliberate, temporary choice to turn it off.
References
- Everyone is turning off Windows Memory integrity: here's why you shouldn't - How-To Geek How-To Geek · 2026-10-09T12:00:14+00:00
- Memory integrity enablement | Microsoft Learn learn.microsoft.com
- Driver Compatibility with Hypervisor-Protected Code Integrity (HVCI) | Microsoft Learn learn.microsoft.com