Microsoft has confirmed that memory integrity protection will be switched on by default on some Windows 11 devices. The change is scheduled for October 2026 on eligible PCs, and it brings stronger kernel-level protection against malicious software and other threats. It can also hurt game performance, which matters a lot to people who aren't running a security-focused enterprise fleet.

What memory integrity actually does

Memory integrity is built on Virtualization-based Security, or VBS. VBS uses the hardware virtualization features in modern processors — Intel's VT-x and AMD's AMD-V — to isolate sensitive data and processes inside Windows. According to Microsoft, this keeps crucial Windows components shielded from outside tampering.

With memory integrity in place, only trusted kernel-mode code and drivers are supposed to run. In theory, unauthorized code can't run loose inside the virtualized Windows environment. Microsoft frames the new default as greater protection with less complexity, and describes it as a foundation for further changes to the Windows security model.

Windows becomes a guest of its own hypervisor

Here's the part that doesn't always get spelled out. VBS requires Windows to run as a "guest" operating system under Hyper-V, Microsoft's built-in hypervisor. Once it's enabled, Hyper-V treats your Windows installation as an isolated virtual machine.

That's a significant change to how Windows runs, and it carries potentially substantial performance implications for certain types of applications. VBS and Hyper-V still work on the same operating principles they always have — what's changed is Microsoft's position that security comes first.

The performance trade-off for gamers

Microsoft has warned before that VBS can hold performance back. The company previously recommended that PC gamers disable the feature, along with Hyper-V's Type-1 virtualization, to significantly improve frame rates.

That advice sits awkwardly next to a default-on rollout. Users are trading some of their full performance for improved security, and for gaming machines specifically, the cost shows up in frame rates.

Microsoft also warns that some applications and device drivers might be incompatible with virtualization-based protections. The company publishes a complete guide to these protections in modern Windows editions.

Who this affects and what stays under your control

The quality updates arriving for Windows 11 next month establish a new, stronger security baseline. But the default isn't a lock:

  • Organizations can change the default configuration by turning off VBS and memory integrity protection.
  • Memory integrity won't be forced onto systems where the option has already been disabled.
  • The rollout applies to eligible Windows 11 PCs, not every machine.

So if you've already turned memory integrity off, the update leaves that choice alone. If you haven't, the decision gets made for you unless you go change it.