Kernel-mode Hardware-enforced Stack Protection can be enabled in Windows 11 version 22H2 (the 2022 Update) and later from Windows Security > Device security > Core isolation details, provided your PC has a supported Intel CET or AMD Shadow Stack CPU and Memory integrity is already enabled. The protection uses a hardware-backed shadow stack to help stop kernel-mode drivers from changing return addresses and redirecting execution. It is a worthwhile security layer, but it can block older or unusually designed drivers and related services, so check compatibility before relying on it.

A glowing shield protects server icons on a microchip beside a verified gear, symbolizing secure technology.Confirm that your PC can use kernel-mode stack protection​

Before changing the setting, save open work and make sure you can restart the PC. Enabling Memory integrity, which this feature requires, may require a restart; a device with incompatible drivers can also lose access to hardware or software that depends on those drivers.

Kernel-mode Hardware-enforced Stack Protection requires:

  • Windows 11 22H2 or later. This guide is specifically for Windows 11; the option is not a general Windows 10 setting.
  • A supported processor with Intel Control-flow Enforcement Technology (CET) or AMD Shadow Stack support. Microsoft identifies Intel 11th Generation Core mobile processors and newer, and AMD Zen 3 processors and newer, as supported examples.
  • Virtualization-based security (VBS) and Hypervisor-protected Code Integrity (HVCI), exposed in Windows Security as Memory integrity.
  • A current Windows Security app. If Windows is fully updated and the option still does not appear, the PC may not meet the CPU or virtualization requirements.

Do not assume that an otherwise modern PC supports this feature just because it runs Windows 11. The Windows Security page only exposes some Core isolation options when the installed hardware, firmware configuration, Windows version, and drivers support them.

Check your Windows version​

  1. Press Windows key + R.
  2. Type the following command, then press Enter:
    winver
  3. Check that the dialog reports Version 22H2 or a later Windows 11 release.
  4. If it is older, open Start > Settings > Windows Update, select Check for updates, install available Windows updates, and restart when prompted.

Check whether virtualization is enabled​

Memory integrity depends on processor virtualization being enabled in the PC’s UEFI firmware.

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Select Performance in the left pane.
  3. Select CPU.
  4. Look near the bottom of the details pane for Virtualization.
  5. If it says Enabled, continue to the next section.
  6. If it says Disabled, do not proceed with the Windows Security toggle yet. You must enable the relevant virtualization setting in the PC’s UEFI/BIOS setup first.

The UEFI setting has different names depending on the processor and PC maker. Common names include Intel Virtualization Technology, Intel VT-x, SVM Mode, or AMD-V. Use the instructions supplied by the PC or motherboard manufacturer for the exact setting. Avoid changing unrelated firmware settings.

Warning: Firmware settings affect startup behavior. Change only the virtualization setting required for Windows security virtualization, save the change, and allow the PC to restart normally. If the PC is managed by an organization, the setting may be controlled by IT.

Turn on Memory integrity first​

Memory integrity is the Windows Security name for HVCI. It is a prerequisite for kernel-mode Hardware-enforced Stack Protection, so enable and restart it before trying to enable the stack-protection setting.

  1. Open Start and search for Windows Security.
  2. Open the Windows Security app.
  3. Select Device security.
  4. Under Core isolation, select Core isolation details.
  5. Find Memory integrity.
  6. Turn the Memory integrity toggle On.
  7. If Windows reports incompatible drivers, select Review incompatible drivers before restarting. Resolve those entries as described later in this guide.
  8. Restart the PC when Windows requests it.

After sign-in, return to Windows Security > Device security > Core isolation details. Confirm that Memory integrity remains switched on.

If Memory integrity switches itself back off, or Windows reports that it cannot be enabled, resolve that issue first. Kernel-mode stack protection cannot run without it.

Enable Kernel-mode Hardware-enforced Stack Protection​

Once Memory integrity is on and the PC has restarted successfully, enable the feature itself.

  1. Open Windows Security.
  2. Select Device security.
  3. Under Core isolation, select Core isolation details.
  4. Locate Kernel-mode Hardware-enforced Stack Protection.
  5. Turn the toggle On.

If the toggle stays on without an error, the feature is configured. Restart the computer if Windows asks you to do so, then sign in normally.

Unlike a conventional antivirus scan or a one-time check, this is a kernel security setting. It protects return addresses as kernel-mode code runs. Windows uses a protected second copy of valid return addresses—known as a shadow stack—to detect a mismatch. If a driver modifies a return address in a way the CPU detects, Windows stops rather than allowing potentially redirected code to continue.

A stop error is therefore a security response, not proof that Windows Security itself has failed. It can also indicate that a required driver or low-level application is incompatible with the protection.

Verify that protection is actually running​

A toggle that is available is not the same as proof that the protection is active. Verify the state after enabling it and, ideally, after at least one normal restart.

Check the Windows Security page​

  1. Open Windows Security > Device security > Core isolation details.
  2. Confirm that both of these settings are On:
    • Memory integrity
    • Kernel-mode Hardware-enforced Stack Protection

If the kernel-mode protection toggle has turned off, select Review incompatible drivers if that option is shown. Do not simply turn it back on repeatedly without resolving the listed conflict.

Verify from System Information​

For a more detailed confirmation, use the built-in System Information utility.

  1. Open Start and type PowerShell.
  2. Right-click Windows PowerShell or Terminal, then select Run as administrator.
  3. Approve the User Account Control prompt.
  4. Run:
    msinfo32.exe
  5. In System Information, keep System Summary selected.
  6. Scroll to the bottom of the right-hand pane.
  7. Review the virtualization-based security entries. A properly enabled configuration should show that VBS is running and list enabled security services. Where supported and active, Windows identifies kernel-mode Hardware-enforced Stack Protection as configured and running.

You can also inspect the same information from an elevated PowerShell session with:

Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard

In the output:

  • VirtualizationBasedSecurityStatus value 2 means VBS is enabled and running.
  • A SecurityServicesConfigured value of 5 means kernel-mode Hardware-enforced Stack Protection is configured.
  • A SecurityServicesRunning value of 5 means kernel-mode Hardware-enforced Stack Protection is running.
  • Value 6 for the kernel-mode stack protection entries indicates Audit mode, which is a policy-managed configuration rather than ordinary full enforcement.

For a personal Windows 11 PC enabled through Windows Security, the important result is that the Windows Security toggle remains on after restart and the WMI output identifies the feature as running.

Resolve incompatible drivers or services​

Windows maintains a list of drivers known to conflict with kernel-mode Hardware-enforced Stack Protection. If one is already installed, Windows may refuse to turn on the feature. If an incompatible driver is installed later, Windows can show “A driver cannot load on this device.”

Some affected applications install a driver only when the app starts. Others use a background service associated with an incompatible driver. That is why Windows may name either a driver or a service in a compatibility warning.

  1. In Windows Security > Device security > Core isolation details, select Review incompatible drivers when it appears.
  2. Record the listed driver file name, publisher, and associated app or device, if Windows provides them.
  3. Check Start > Settings > Windows Update and install all available updates. Restart if requested.
  4. Get a current compatible driver directly from the device manufacturer or the publisher of the associated application.
  5. Install the update and restart the PC.
  6. Return to Core isolation details and try enabling kernel-mode Hardware-enforced Stack Protection again.

If no compatible update exists, remove the application that installed the incompatible driver only if you no longer need its functionality.

Warning: Do not delete .sys driver files manually from the Windows folders. Removing a driver file directly can leave a broken service, prevent a device from starting, or make Windows unstable. Remove the related application or device software through its supported uninstaller instead.

To remove a no-longer-needed application:

  1. Open Start > Settings > Apps > Installed apps.
  2. Find the application associated with the incompatible driver.
  3. Select the More button beside it.
  4. Select Uninstall.
  5. Complete the vendor uninstaller, then restart.
  6. Check Windows Security again and enable the protection.

For a specific device driver, first check Windows Update. If the vendor identifies the affected device and provides a newer driver, you can also use Device Manager:

  1. Open Start, type Device Manager, and open it.
  2. Expand the category that contains the affected hardware.
  3. Right-click the device and select Update driver.
  4. Select Search automatically for drivers.
  5. Follow the prompts and restart if Windows installs an update.

If the incompatible component belongs to security software, disk tools, anti-cheat software, input customization utilities, hardware monitoring software, or an older peripheral utility, check that product’s support documentation before removal. These classes of software are more likely to depend on low-level drivers.

Turn the feature back off if it causes a problem​

Keep the protection enabled when possible. Turning it off reduces defense against kernel-mode return-address manipulation. However, temporarily disabling it is an appropriate rollback if a necessary application or device can no longer work and no compatible update is available.

  1. Open Windows Security > Device security > Core isolation details.
  2. Turn Kernel-mode Hardware-enforced Stack Protection Off.
  3. Restart if Windows requests it.
  4. Test the affected device or application again.
  5. When a compatible driver becomes available, install it, restart, and turn the protection back on.

Turning off kernel-mode Hardware-enforced Stack Protection does not require you to turn off Memory integrity. Leave Memory integrity enabled unless it is specifically implicated in the compatibility issue.

If Windows cannot start normally after enabling Memory integrity or related VBS protections, use Windows Recovery Environment rather than repeatedly forcing normal boot.

  1. From the sign-in screen, hold Shift while selecting Power > Restart.
  2. Select Troubleshoot > Advanced options > Command Prompt.
  3. Sign in if Windows asks for an administrator account.
  4. Run:
    reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /v "Enabled" /t REG_DWORD /d 0 /f
  5. Close Command Prompt and select Continue to restart Windows.

This recovery command disables Memory integrity, which also removes the prerequisite for kernel-mode Hardware-enforced Stack Protection. After Windows starts, update or remove the conflicting driver before enabling Memory integrity and stack protection again.

If Memory integrity was deployed with a UEFI lock by an organization, do not attempt to work around the policy. The device may require IT administration or UEFI changes, and disabling Secure Boot can be necessary for recovery in that configuration.