Starting with the October 13, 2026 Patch Tuesday update, Microsoft will switch on Memory Integrity by default for eligible Windows 11 PCs, closing a gap that has left millions of capable machines running without the protection for years.
The feature has existed for a while, but a large number of qualifying devices never had it turned on. This change removes the need for anyone to manually flip a setting, at least on hardware that passes Microsoft’s readiness checks.
What Is Memory Integrity and Why Microsoft Wants It On
Memory Integrity is also known as Hypervisor-protected Code Integrity, or HVCI. It works on top of Virtualization-based Security (VBS), using your CPU’s virtualization hardware to carve out an isolated environment that the rest of Windows cannot reach directly.
Kernel-mode drivers, the lowest-level software running on your machine, must pass through this isolated checker before Windows lets them execute. Malware that tries to sneak in through a vulnerable or unsigned driver gets stopped at this layer instead of reaching the kernel.
Which Windows 11 PCs Get It Automatically in October 2026
Not every Windows 11 PC qualifies, but Microsoft’s hardware requirements for automatic enablement are fairly lenient. To be in the running, a device needs at least one of the following processors: an Intel 8th-generation processor or newer, an AMD Zen 2 or newer, or a Qualcomm Snapdragon 8180 or newer.
On top of that, x64 systems need at least 8GB of RAM, a 64GB SSD, virtualization enabled in firmware, and drivers that are already confirmed compatible with memory integrity.
Secured-core PCs, the certification tier Microsoft and OEMs apply to business and enterprise hardware, already ship with the feature turned on today.
How Microsoft Decides Whether to Flip the Switch
Before enabling the feature, Windows runs a readiness assessment on each device rather than pushing the change to every PC that merely meets the minimum hardware. This gives Microsoft a chance to catch problems before they reach your screen.
If you have already turned Memory Integrity off on purpose, whether through Group Policy, Intune, or a manual registry change, Windows Update will respect that choice and leave it alone. The rollout is an opt-out by policy, not a forced override.
To check the current state, open Windows Security > Device security > Core isolation, where the Memory integrity toggle shows On or Off directly on the page.
Why Microsoft Is Pushing This Now
Windows security has faced a different kind of pressure recently. AI-assisted vulnerability research has become fast enough that researchers, and presumably attackers, can find kernel-level bugs in Windows much quicker than before.
Turning on a piece of protection that was already unused on millions of eligible PCs is a low-cost way to close off an entire class of attack without waiting for a slower fix elsewhere in the operating system.
Memory Integrity was never a Windows 11 exclusive. It shipped as an opt-in VBS feature going back to Windows 10, and became the default only on clean installs of Windows 10 in S mode, and later Windows 11 on qualifying hardware. Millions of PCs were upgraded rather than clean-installed over the years, and those are exactly the devices this October update targets.
Should You Turn Memory Integrity Off? What This Means for You
In practice, incompatible drivers are the main reason this protection has not been on for everyone already. A driver written years ago that accesses memory in ways Memory Integrity does not allow will be blocked from loading, and in worse cases, that has caused boot failures on older hardware in the past.
If your PC gets the feature switched on and something breaks, Windows Security will flag it under Core isolation, and the CodeIntegrity event log will name the offending driver. You can find those conflicts under Event Viewer, in Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational, tagged with Event ID 3087 when a driver gets flagged as incompatible.
From there, your options are straightforward: wait for an updated driver from the manufacturer, or turn the feature off manually while you wait. PCs that have had Memory Integrity enabled for years have lived with this trade-off, and the same playbook applies now.
IT admins managing a fleet can pre-configure the feature through registry keys under HKLM\System\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity, or manage it at scale through Group Policy and Intune. For most users, there is nothing to do: if your device qualifies and passes the readiness check, Memory Integrity turns on automatically with the October 13 update. Just keep Windows Update installing updates, and glance at Windows Security’s Core isolation page afterward to confirm the switch flipped. If you rely on older peripherals or custom hardware, check with the manufacturer for compatible drivers before the update lands.
Source: Windows Latest
Over to you: Will you leave Memory Integrity on after this update, or switch it off if an older driver breaks?



