Criar
Microsoft to Turn on Windows 11 Kernel Protection by Default

Microsoft to Turn on Windows 11 Kernel Protection by Default

Microsoft announced a staged Windows 11 security rollout that will automatically enable Memory Integrity on compatible PCs starting in October 2026. The first update with the change will arrive on Patch Tuesday, October 13, and Microsoft says it will apply only to systems that meet its requirements.

Memory Integrity is also known as HVCI, or Hypervisor-protected Code Integrity. It uses hardware virtualization to create an isolated environment where each driver is checked before it runs, and turning it on also enables Virtualization-Based Security, or VBS.

Windows 11 security settings: core isolation
Windows 11 security settings: core isolation

The automatic enablement applies only to devices with an Intel 8th generation processor or newer, AMD Zen 2 or newer, or Qualcomm Snapdragon 8180 or newer, as well as at least 8 GB of RAM and a 64 GB SSD. Microsoft also says the rollout will be gradual, so compatible PCs may not receive the change at the same time.

If Memory Integrity was already disabled through Group Policy, Intune, or the registry, Windows Update will not force it back on. That means existing user settings and organizational policies will remain in place even after the update arrives.

Windows 11 security settings: Memory integrity enabled
Windows 11 security settings: Memory integrity enabled

The change may not be welcome on every system. Reports say Memory Integrity can affect gaming performance on some PCs and may interfere with undervolting tools such as ThrottleStop and Intel XTU. In that context, Microsoft's push for stronger kernel-level protection raises a familiar question for PC owners who care about every frame and every tweak.

Will Windows 11 users accept stronger kernel protection if it can affect gaming performance and undervolting tools?

    Sobre o autor
    Comentários0