Windows IT Pro Blog:
Security works best when protection is built in, not bolted on.
Beginning in October 2026, Microsoft will expand memory integrity protection across eligible devices, helping you and your organization benefit from stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration. This change reduces security complexity while helping you establish a stronger security baseline across your environment.
Built on Virtualization-based Security (VBS), memory integrity helps protect critical parts of Windows from tampering. It forms a foundation for modern security innovations such as hotpatch updates that improve user experience and productivity, as well as protection.
Making advanced security the easier choice
More devices will soon receive stronger protection by default, with no additional setup required. Windows quality updates will begin enabling memory integrity protection on eligible devices. If not already enabled, these updates will also enable VBS, helping make additional security capabilities available and reflecting our commitment to making Windows secure by design and secure by default.To help ensure a reliable device experience, Windows automatically evaluates readiness before enabling memory integrity. Readiness signals include hardware capabilities, compatibility, and performance considerations. For more detail on requirements, see our Memory integrity and VBS enablement documentation.
Recommended by Microsoft, controlled by you
Windows provides a recommended security baseline, while respecting organizational choice. While most eligible devices will benefit automatically from memory integrity protection, you retain full control over your security configuration. Existing administrator and user decisions and policies remain in effect. This means that devices where memory integrity has already been disabled won't be automatically changed by this rollout.If memory integrity is not enabled by default, users and organizations can still review, configure, and enable it using existing Windows security and management tools. For step-by-step guidance, see Enable memory integrity.
Enable or Disable Core Isolation Memory Integrity in Windows 11
This tutorial will show you how to turn on or off core isolation memory integrity in Windows 11. Core isolation is a security feature of Microsoft Windows that protects important core processes of Windows from malicious software by isolating them in memory. It does this by running those core...
www.elevenforum.com
Stronger protection today, a foundation for tomorrow
By expanding memory integrity protection across eligible Windows devices, Microsoft is helping you establish a stronger security foundation, reduce configuration burden, and prepare for the next generation of Windows security innovations. Soon, more devices will be protected against attacks that attempt to compromise the Windows kernel and gain control of critical operating system functions. Memory integrity helps make this possible by allowing only trusted kernel-mode code and drivers to run. More protection. Less complexity. A stronger foundation for what's next.For more information on memory integrity, see:
- Enable memory integrity.
- Memory integrity enablement
- Windows 11 security book - Silicon assisted security
- Virtualization-based Security (VBS)
Source:
Expanding memory integrity protection across Windows devices - Windows IT Pro Blog
Learn how you can benefit from stronger kernel-level protection from sophisticated attacks by default.









