Microsoft will soon enable memory integrity by default on eligible Windows 11 PCs

Users will sacrifice full performance for improved security

by · TechSpot

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

The big picture: Microsoft will soon enable a security feature designed to take advantage of virtualization capabilities available in modern x86 processors. However, the company doesn't clearly explain that this represents a significant change to how Windows runs, with potentially substantial performance implications for some types of applications.

Microsoft recently confirmed that memory integrity protection will soon be enabled by default on some Windows 11 devices. The change will arrive in October 2026 for eligible Windows PCs and will provide stronger kernel-level protection against malicious software and other threats. However, it could also have a detrimental effect on game performance, which is likely a significant concern for consumers who aren't part of a security-focused enterprise organization.

Memory integrity protection is built upon Virtualization-based Security (VBS), a technology designed to leverage hardware-level virtualization capabilities in Intel (VT-x) and AMD (AMD-V) CPUs to isolate sensitive data and processes within Windows. VBS protects crucial Windows components from external tampering, Microsoft explains.

However, VBS requires Windows to become a "guest" operating system running under Hyper-V, Microsoft's native hypervisor. Once enabled, Hyper-V treats the Windows installation as an isolated virtual machine. Microsoft previously warned that VBS could hinder performance, recommending that PC gamers disable the feature (along with Hyper-V's Type-1 virtualization) to significantly improve frame rates.

VBS and Hyper-V are still based on the same operating principles. However, Microsoft has now decided that security comes first and that VBS-based memory integrity protection should be enabled by default. Quality updates coming to Windows 11 next month will establish a new, stronger security baseline, but organizations will be able to change the default configuration by disabling VBS and memory integrity protection.

Furthermore, memory integrity will not be forced on systems where the option has already been disabled. Microsoft provides a complete guide to virtualization-based protections in modern Windows editions, warning that "some" applications and device drivers might be incompatible with this technology.

// Related Stories

Memory integrity should theoretically prevent unauthorized code from running amok in a virtualized Windows environment, allowing only trusted kernel-mode code and drivers to run. Microsoft said the new option will provide greater protection while reducing complexity, establishing a new "foundation" for upcoming changes to the Windows security model.

See more TechSpot in Google Add us as a preferred source and our reporting shows up first when you search.
Add TechSpot