Microsoft Expands Memory Integrity Protection Despite Compatibility Concerns

Microsoft wants stronger kernel-level security to become the norm, but some organizations may need to evaluate how older hardware and drivers will handle the change.

Windows 11

Key Takeaways:

  • Microsoft will begin enabling Memory Integrity on more eligible Windows 11 devices in October 2026.
  • This feature helps protect Windows against kernel-level attacks using Virtualization-based Security.
  • Older hardware and incompatible drivers remain a consideration, which is why Microsoft is using a phased rollout approach.

Microsoft plans to automatically enable Memory Integrity protection on more eligible Windows 11 devices. This security feature, which is designed to strengthen defenses against attacks, will begin rolling out in October 2026.

Memory Integrity is designed to strengthen defenses against attacks that target the Windows kernel by ensuring that only trusted drivers and kernel-level code can run on a system. It relies on Virtualization-based Security (VBS) and is already enabled by default on Secured-core PCs and many clean installations of Windows 11.

“Beginning in October 2026, Microsoft will expand memory integrity protection across eligible devices, helping you and your organization benefit from stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration,” Microsoft explained.

According to Microsoft, Windows 11 will assess whether a device is suitable based on factors such as hardware support, driver compatibility, and overall performance impact. Microsoft says the goal is to improve security while minimizing disruptions for users and organizations. The company will not automatically re-enable Memory Integrity on devices where users or IT administrators have previously disabled it.

Potential performance and compatibility concerns

Microsoft acknowledges that Memory Integrity can affect performance on older hardware. Windows 11 devices powered by newer Intel and AMD processors handle the feature more efficiently, but older processors may experience greater performance overhead. Some older applications and hardware drivers may also be incompatible with the protection mechanism, which is why Microsoft is taking a phased approach to the rollout.

This move reflects Microsoft’s ongoing effort to make advanced security protections the default on Windows 11. The company is expanding Memory Integrity to more systems automatically to reduce the risk of kernel-level attacks without requiring manual configuration from users or IT teams, while still avoiding devices that could face compatibility or performance problems.