With the aid of artificial intelligence, the number of vulnerabilities discovered and fixed in Windows 11 has repeatedly reached new heights. This has led Microsoft to pay closer attention to system security and to seek higher-grade protection to bolster it. For Microsoft, the simplest measure is to enable memory integrity protection, a feature that enforces more robust kernel-level defence.
Memory Integrity Becomes Enabled by Default
Beginning in October 2026, Microsoft will enforce kernel-level protection by default on Windows 11 devices that meet the hardware requirements. The kernel-level protection in question is memory integrity, also known as Hypervisor-protected Code Integrity (HVCI). The feature has long been available but is typically not enabled by default, since turning it on affects overall PC performance.
Memory integrity is built on VBS virtualization-security technology. It uses hardware virtualization to create an isolated environment in which processes run, so that even if malware hijacks a process, it cannot break out of the sandbox isolation. As a result, it cannot obtain elevated operating privileges through kernel-level access to wreak havoc.
It Does Affect Gaming Performance
The principal reason Microsoft has not enabled memory integrity by default before is that the feature relies on hardware virtualization, which inevitably affects overall PC performance once enabled. For this reason, Microsoft has generally refrained from turning it on by default, or has enabled it by default only on newly launched PCs. Microsoft’s own documentation covers how to enable and manage the feature.
The impact on performance depends on the user’s scenario:
- Everyday office work, study, and web browsing: The impact is negligible.
- Gaming on a not-too-old CPU: Average frame rates drop by roughly 5% to 10%, and certain games may fall considerably more.
- Low-resolution and CPU-bound games: The impact is more pronounced, and frame drops should be fairly common.
- Gaming on an older CPU: The impact is substantial.
Users Can Decide for Themselves
Users can decide for themselves whether to enable it. The setting is located at: Windows Security, Device security, Core isolation / Core isolation details, Memory integrity. Previously, once memory integrity was turned off, it could not be re-enabled without reinstalling the system. Now, however, it can be switched on or off at any time.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!