Microsoft is about to flip a security switch on millions of Windows 11 PCs, and most people won’t even notice it happening — which is kind of the point.
Starting in October 2026, Windows quality updates will begin automatically turning on memory integrity protection for eligible devices, according to a Windows IT Pro Blog post from Peter Waxman, a group program manager at Microsoft. If a device doesn’t already have Virtualization-based Security (VBS) enabled, that will get switched on too, laying the groundwork for the feature. Microsoft frames this as making “advanced security the easier choice” rather than something IT admins and power users have to dig through settings to turn on themselves.
What is Memory Integrity?
So what actually is memory integrity? It’s a Virtualization-based Security (VBS) feature (also known as Hypervisor-protected Code Integrity, or HVCI, if you’ve poked around Core Isolation settings before) that locks down critical parts of the Windows kernel so only trusted, verified code and drivers can run there. That matters because a lot of sophisticated malware tries to sneak in through the kernel to gain deep control over a system.
With memory integrity running, Windows checks code inside an isolated, hardware-backed environment before it’s allowed to execute, which makes that kind of attack a lot harder to pull off. It’s the same VBS enclave technology Microsoft leaned on to lock down the Recall feature after its rocky rollout, so this isn’t a brand-new concept — Microsoft is just extending it to more devices by default.
Before you panic and go check your settings, here’s the reassuring part: Microsoft isn’t going to force this on everyone blindly. Windows will automatically evaluate whether a device is actually ready first — looking at hardware capabilities, driver compatibility, and performance — before flipping the switch. And if you (or your IT department) already turned memory integrity off on purpose, this rollout won’t override that decision. Your existing policies and settings stay in effect.

That last bit is worth calling out for anyone who games on their PC, because this is not a purely theoretical concern. Memory integrity has historically had a real, measurable performance cost on some systems, particularly with older CPUs, and some gamers have deliberately disabled it in the past to squeeze out extra frame rates in demanding titles. If that’s you, this update won’t force it back on, but it’s a good moment to check your Core Isolation settings and decide what trade-off makes sense for your setup.
If you want to check where your PC currently stands, open Windows Security, head to Device Security, then Core Isolation Details, and look at the Memory Integrity toggle. If it’s off and you want the extra protection, you can turn it on manually right now rather than waiting for the October rollout — Microsoft has a full guide for that in its memory integrity enablement documentation. If it’s already on, there’s nothing else to do; you’re getting ahead of the curve for free.
Zooming out, this fits a pattern Microsoft has been leaning into hard lately as part of its broader Windows Resiliency Initiative: building security in by default rather than expecting users and IT admins to configure it themselves. Memory integrity is also described as a foundation for other features coming down the line, including hotpatch updates that let Windows patch security flaws without forcing a reboot, so this isn’t just a one-off toggle — it’s Microsoft setting up the plumbing for where Windows security is headed next.

For organizations managing fleets of Windows devices, it’s worth reviewing device readiness ahead of October so there aren’t any surprises when quality updates start rolling this out, especially on hardware running older or less common drivers. Microsoft’s own memory integrity and VBS enablement documentation breaks down the hardware requirements in detail if you want to get ahead of it.
About The Author
Discover more from Microsoft News Now
Subscribe to get the latest posts sent to your email.