Kernel-Mode Hardware-enforced Stack Protection suddenly off?


I found somewhere that disabling "Memory integrity" and re-enabling it could help with getting Kernel-mode Hardware-enforcement Stack Protection enabled, but I was only able to enable memory integrity again by manually enabling it in the registry. I would recommend against disabling this setting until the problems with kernel enforcement are resolved as they appear to be linked

Additionally, I'm guessing the "Review Incompatible Drivers" is supposed to give a list of incompatible drivers. I have no list and only a link where Microsoft recommends against uninstalling drivers to resolve the issue

I have updated every driver I could find from Dell, but the issue still persists. (Dell Latitude 3420)
View attachment 58997
A-ha, so we can expect a fix from Microsoft for being locked out of the Kernel-mode Hardware-enforcement Stack Protection? That would be neat.
 

My Computer

System One

  • OS
    Windows 11 Pro 22H2 - OS Build 22621.1555
    Computer type
    PC/Desktop
    CPU
    13900 KS
    Motherboard
    MSI Z790 Godlike
    Memory
    128 GB Kingston 5200Mhz
    Graphics Card(s)
    Gigabyte RTX 4090 Gaming 24 OC
    Sound Card
    Motherboard integrated
    Monitor(s) Displays
    34" LG 34GP950G-B 144hz / 27" Asus 144hz / 22" AOC
    Screen Resolution
    3440 x 1440 / 2560 x 1440 / 1920 x 1080
    Hard Drives
    2 TB Samsung 980 PRO MZ-V8P2T0BW
    4 TB Kingston SFYRD/4000G
    8 TB Samsung MZ-77Q8T0BW
    18TB Seagate IronWolf Pro
    PSU
    Corsair AX 1600i
    Case
    Corsair 7000 D
    Cooling
    Arctic Liquid Freezer II 420mm
    Keyboard
    Steelseries ApexPro
    Mouse
    Logitech G-Pro Superlight
    Internet Speed
    500Mbit / 150Mbit
    Browser
    Chrome (with plugins uBlock Origin, Poper Blocker, ScriptSafe)
    Antivirus
    Kaspersky Total Security
Just enabled the Kernel Mode setting and restarted and now find I've lost (no biggie) the picture on the Search Box. It is still enabled in settings I think.

Screenshot 2023-04-29 103707.png

Screenshot 2023-04-29 104334.png
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
Also found this morning that 'Night Light' is not behaving correctly. It has worked for weeks perfectly up to this point. All this is to much of a coincidence.

Have turned the Kernel Mode setting back to off.
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
Today the Kernel-Mode Hardware section in the Security settings have been replaced with a Microsoft Vulnerable Driver Blocklist section with a toggle set to "on" but grayed out. The shield icon in the task tray still shows a yellow exclamation point and the Settings home page under Device Security states that Local Security Authority protection is off.
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 5510
    CPU
    11th Gen Intel(R) Core(TM) i7-11390H @ 3.40GHz
    Memory
    16 GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB SSD
I'm seeing that as well.

In fact following my posts just above these I went back to have another go with the view of turning it back on again and found the option had disappeared. As I mentioned in another thread (and its replies):

This is puzzling me as well although if I'm honest I prefer the Bing icon... but I would just like to know what happened.

For me this coincided exactly with me enabling the 'Kernel Mode' that I kept being nagged about. I had the picture before enabling this feature and doing the requested restart. Following the restart and it was gone. I disabled the Kernel Mode again but no pictures now.

Kernel-Mode Hardware-enforced Stack Protection suddenly off?

Coincidence or...

The big problem in all this is just not having a clue when something changes by design or whether something has broken or whether you have done something and don't know what that was.

I was left thinking that having enabled, then disabled that something had broken.
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
I do not seem to be having issue with this. I was able to turn KMHE Stack Protection on and have had no ill effects yet.
I'm wondering if it might have something to do with a local configuration issue.

I'm on W11 22H2 22621.1555

My current Windows Defender Settings:

_
WD 1.jpg

_
WD 2.jpg
_
WD 3.jpg

I have not installed this Windows Update Preview as of yet:
_
WU 1.jpg
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel i7-13700K
    Motherboard
    MSI PRO Z790-A WiFi
    Memory
    Corsair Vengence 5600 - 32GB
    Graphics Card(s)
    MSI RTX3060 Ventus 2x 12GB
    Sound Card
    On board - Realtek ALC4080
    Monitor(s) Displays
    LG 27GL850
    Screen Resolution
    2560 x 1440
    Hard Drives
    WD Black SN850X Nvme - 1TB
    WD Black 6TB HDD 256MB cache CMR
    WD Black 6TB HDD 128MB cache CMR
    PSU
    Corsair RM850x
    Case
    Fractal Design - Define 7
    Cooling
    Deepcool AK400
    Keyboard
    MS KC0405
    Mouse
    MS Model 1113 / MS Wireless Mobile Mouse 3500
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
    Other Info
    I have a Case Speaker!
    I have a Blueray Disk drive!
  • Operating System
    Windows 10 Pro 22H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    i7-9700K
    Motherboard
    Asus Prime Z390-A
    Memory
    Corsair Vengence 32GB
    Graphics card(s)
    EVGA GTX1060
    Sound Card
    On Board
    Monitor(s) Displays
    Acer 27"
    Screen Resolution
    1920 x 1080
    Hard Drives
    WD Black Nvme 500GB
    Toshiba X300 5TB
    PSU
    Corsair RM850x
    Case
    Antec P101 Silent
    Cooling
    CoolerMaster Hyper T4
    Mouse
    Logitec M-U0007
    Keyboard
    MS KC0405
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Avast!
    Other Info
    I have a Case Speaker!
I'm now missing the 'Kernel Mode Hardware Stack'. I'm assuming it disappeared after I decided to disable it as a test although I did not immediately look to see... I never dreamt it would just disappear. For curiosity I tried SFC and DISM but no issues found.

Screenshot 2023-05-07 181612.png
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
Have you installed WU KB5025305 yet?
How did you disable KMHE Stack Protection?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel i7-13700K
    Motherboard
    MSI PRO Z790-A WiFi
    Memory
    Corsair Vengence 5600 - 32GB
    Graphics Card(s)
    MSI RTX3060 Ventus 2x 12GB
    Sound Card
    On board - Realtek ALC4080
    Monitor(s) Displays
    LG 27GL850
    Screen Resolution
    2560 x 1440
    Hard Drives
    WD Black SN850X Nvme - 1TB
    WD Black 6TB HDD 256MB cache CMR
    WD Black 6TB HDD 128MB cache CMR
    PSU
    Corsair RM850x
    Case
    Fractal Design - Define 7
    Cooling
    Deepcool AK400
    Keyboard
    MS KC0405
    Mouse
    MS Model 1113 / MS Wireless Mobile Mouse 3500
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
    Other Info
    I have a Case Speaker!
    I have a Blueray Disk drive!
  • Operating System
    Windows 10 Pro 22H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    i7-9700K
    Motherboard
    Asus Prime Z390-A
    Memory
    Corsair Vengence 32GB
    Graphics card(s)
    EVGA GTX1060
    Sound Card
    On Board
    Monitor(s) Displays
    Acer 27"
    Screen Resolution
    1920 x 1080
    Hard Drives
    WD Black Nvme 500GB
    Toshiba X300 5TB
    PSU
    Corsair RM850x
    Case
    Antec P101 Silent
    Cooling
    CoolerMaster Hyper T4
    Mouse
    Logitec M-U0007
    Keyboard
    MS KC0405
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Avast!
    Other Info
    I have a Case Speaker!
Interesting that Microsoft Vulnerable Driver Blocklist is ON and greyed out.
That will be annoying when testing various drivers.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel i7-13700K
    Motherboard
    MSI PRO Z790-A WiFi
    Memory
    Corsair Vengence 5600 - 32GB
    Graphics Card(s)
    MSI RTX3060 Ventus 2x 12GB
    Sound Card
    On board - Realtek ALC4080
    Monitor(s) Displays
    LG 27GL850
    Screen Resolution
    2560 x 1440
    Hard Drives
    WD Black SN850X Nvme - 1TB
    WD Black 6TB HDD 256MB cache CMR
    WD Black 6TB HDD 128MB cache CMR
    PSU
    Corsair RM850x
    Case
    Fractal Design - Define 7
    Cooling
    Deepcool AK400
    Keyboard
    MS KC0405
    Mouse
    MS Model 1113 / MS Wireless Mobile Mouse 3500
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
    Other Info
    I have a Case Speaker!
    I have a Blueray Disk drive!
  • Operating System
    Windows 10 Pro 22H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    i7-9700K
    Motherboard
    Asus Prime Z390-A
    Memory
    Corsair Vengence 32GB
    Graphics card(s)
    EVGA GTX1060
    Sound Card
    On Board
    Monitor(s) Displays
    Acer 27"
    Screen Resolution
    1920 x 1080
    Hard Drives
    WD Black Nvme 500GB
    Toshiba X300 5TB
    PSU
    Corsair RM850x
    Case
    Antec P101 Silent
    Cooling
    CoolerMaster Hyper T4
    Mouse
    Logitec M-U0007
    Keyboard
    MS KC0405
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Avast!
    Other Info
    I have a Case Speaker!
I am also missing "Microsoft Defender Credential Guard". I have installed WU KB5025305 and KB4023057.

I'm on W11 22H2 22621.1631
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 5510
    CPU
    11th Gen Intel(R) Core(TM) i7-11390H @ 3.40GHz
    Memory
    16 GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    512 GB SSD
Have you installed WU KB5025305 yet?
How did you disable KMHE Stack Protection?
Who, you mean me?

Yes that update was installed on 26th April.

I did have the button for Kernel Mode protection but after turning it on and then off the next day it disappeared for good.
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
It seems that many users are seeing different options/features enabled/disabled or not showing at all - despite running the same versions of Windows and Security updates!

Nothing like being inconsistent
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2 (RP channel)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    AMD Ryzen 5900X 12-core
    Motherboard
    X570 Aorus Xtreme
    Memory
    64GB Corsair Platinum RGB 3600MHz CL16
    Graphics Card(s)
    MSI Suprim X 3080 Ti
    Sound Card
    Soundblaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming VG289Q
    Screen Resolution
    3840x2160
    Hard Drives
    Samsung 990 Pro 2TB
    Samsung 980 Pro 2TB
    Samsung 970 Evo Plus 1TB
    Samsung 870 Evo 4TB
    Samsung T7 Touch 1TB
    PSU
    Asus ROG Strix 1000W
    Case
    Corsair D750 Airflow
    Cooling
    Noctua NH-D15S
    Keyboard
    Asus ROG Flare
    Mouse
    Logitech G903 with PowerPlay charger
    Internet Speed
    500Mb/sec
    Browser
    Microsoft Edge
    Antivirus
    Windows Defender
For the first time in months i don't have windows security telling me that the system is vulnerable. But.. LSA and Kernel Mode protection settings have disappeared completely.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    CPU
    Ryzen 7 5700X
    Motherboard
    ASUS Crosshair VII Hero
    Memory
    32GB 3600MHZ CL16
    Graphics Card(s)
    RTX3070TI
    Monitor(s) Displays
    LG27GP850-B
    Screen Resolution
    2560x1440
    PSU
    Corsair RM750x
    Case
    Fractal Design Meshify 2
    Cooling
    Noctua NH-D15s
    Keyboard
    ASUS Strix Flare
    Mouse
    Glorious Model D- Wireless
    Browser
    MS Edge
I'm trying to determine if the latest update (KB5025305) will remove both LSA and Kernal Mode settings before I install it.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel i7-13700K
    Motherboard
    MSI PRO Z790-A WiFi
    Memory
    Corsair Vengence 5600 - 32GB
    Graphics Card(s)
    MSI RTX3060 Ventus 2x 12GB
    Sound Card
    On board - Realtek ALC4080
    Monitor(s) Displays
    LG 27GL850
    Screen Resolution
    2560 x 1440
    Hard Drives
    WD Black SN850X Nvme - 1TB
    WD Black 6TB HDD 256MB cache CMR
    WD Black 6TB HDD 128MB cache CMR
    PSU
    Corsair RM850x
    Case
    Fractal Design - Define 7
    Cooling
    Deepcool AK400
    Keyboard
    MS KC0405
    Mouse
    MS Model 1113 / MS Wireless Mobile Mouse 3500
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
    Other Info
    I have a Case Speaker!
    I have a Blueray Disk drive!
  • Operating System
    Windows 10 Pro 22H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    i7-9700K
    Motherboard
    Asus Prime Z390-A
    Memory
    Corsair Vengence 32GB
    Graphics card(s)
    EVGA GTX1060
    Sound Card
    On Board
    Monitor(s) Displays
    Acer 27"
    Screen Resolution
    1920 x 1080
    Hard Drives
    WD Black Nvme 500GB
    Toshiba X300 5TB
    PSU
    Corsair RM850x
    Case
    Antec P101 Silent
    Cooling
    CoolerMaster Hyper T4
    Mouse
    Logitec M-U0007
    Keyboard
    MS KC0405
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Avast!
    Other Info
    I have a Case Speaker!
I never installed KB5025305 and KB4023057, and they disappeared and KB5026372 took their place.
I just installed KB5026372 and there is no change to my Defender Core Isolation settings. KMHE Stack Protection is still there and ON.

I suspect that this difference issue has to do with your processor and motherboard's security capabilities.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel i7-13700K
    Motherboard
    MSI PRO Z790-A WiFi
    Memory
    Corsair Vengence 5600 - 32GB
    Graphics Card(s)
    MSI RTX3060 Ventus 2x 12GB
    Sound Card
    On board - Realtek ALC4080
    Monitor(s) Displays
    LG 27GL850
    Screen Resolution
    2560 x 1440
    Hard Drives
    WD Black SN850X Nvme - 1TB
    WD Black 6TB HDD 256MB cache CMR
    WD Black 6TB HDD 128MB cache CMR
    PSU
    Corsair RM850x
    Case
    Fractal Design - Define 7
    Cooling
    Deepcool AK400
    Keyboard
    MS KC0405
    Mouse
    MS Model 1113 / MS Wireless Mobile Mouse 3500
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
    Other Info
    I have a Case Speaker!
    I have a Blueray Disk drive!
  • Operating System
    Windows 10 Pro 22H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    i7-9700K
    Motherboard
    Asus Prime Z390-A
    Memory
    Corsair Vengence 32GB
    Graphics card(s)
    EVGA GTX1060
    Sound Card
    On Board
    Monitor(s) Displays
    Acer 27"
    Screen Resolution
    1920 x 1080
    Hard Drives
    WD Black Nvme 500GB
    Toshiba X300 5TB
    PSU
    Corsair RM850x
    Case
    Antec P101 Silent
    Cooling
    CoolerMaster Hyper T4
    Mouse
    Logitec M-U0007
    Keyboard
    MS KC0405
    Internet Speed
    940 Mbps
    Browser
    Firefox
    Antivirus
    Avast!
    Other Info
    I have a Case Speaker!
The most recent update KB5026372 seems to have removed the toggle for Kernel-mode Hardware-enforcement stack for me

Before this whole Kernel enforcement setting was introduced, I had Memory integrity enabled but now it has to be manually enabled in the registry. I still have a blank list of incompatible drivers even though that was supposed to be one of the main fixes in KB5026372
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Dell Latitude 3420
    CPU
    i7-1165G7
    Memory
    16gb

Latest Support Threads

Back
Top Bottom