Microsoft will soon enable memory integrity by default on eligible Windows 11 PCs

Alfonso Maruccia

Posts: 2,691   +1,015
Staff
The big picture: Microsoft will soon enable a security feature designed to take advantage of virtualization capabilities available in modern x86 processors. However, the company doesn't clearly explain that this represents a significant change to how Windows runs, with potentially substantial performance implications for some types of applications.

Microsoft recently confirmed that memory integrity protection will soon be enabled by default on some Windows 11 devices. The change will arrive in October 2026 for eligible Windows PCs and will provide stronger kernel-level protection against malicious software and other threats. However, it could also have a detrimental effect on game performance, which is likely a significant concern for consumers who aren't part of a security-focused enterprise organization.

Memory integrity protection is built upon Virtualization-based Security (VBS), a technology designed to leverage hardware-level virtualization capabilities in Intel (VT-x) and AMD (AMD-V) CPUs to isolate sensitive data and processes within Windows. VBS protects crucial Windows components from external tampering, Microsoft explains.

However, VBS requires Windows to become a "guest" operating system running under Hyper-V, Microsoft's native hypervisor. Once enabled, Hyper-V treats the Windows installation as an isolated virtual machine. Microsoft previously warned that VBS could hinder performance, recommending that PC gamers disable the feature (along with Hyper-V's Type-1 virtualization) to significantly improve frame rates.

VBS and Hyper-V are still based on the same operating principles. However, Microsoft has now decided that security comes first and that VBS-based memory integrity protection should be enabled by default. Quality updates coming to Windows 11 next month will establish a new, stronger security baseline, but organizations will be able to change the default configuration by disabling VBS and memory integrity protection.

Furthermore, memory integrity will not be forced on systems where the option has already been disabled. Microsoft provides a complete guide to virtualization-based protections in modern Windows editions, warning that "some" applications and device drivers might be incompatible with this technology.

Memory integrity should theoretically prevent unauthorized code from running amok in a virtualized Windows environment, allowing only trusted kernel-mode code and drivers to run. Microsoft said the new option will provide greater protection while reducing complexity, establishing a new "foundation" for upcoming changes to the Windows security model.

Permalink to story:

 
I happily switched to an M4 Mac Mini and an M5 MacBook Air on Saturday.
I'll probably keep my Windows10 PC's during data migration etc., make my main PC my comics box and put what's now my comics box in storage or pass it on.
MacOS setup is a BLESSING compared to the Windows variety and took about FIVE MINUTES (iPhone sync).
Also, while my Windows10 i9 box is certainly no slouch the M5 MacBook is more than TWICE as fast, and easily the fastest computer I've ever laid hands on.
Apple's more expensive but IMO well worth the money and I'm somewhat sorry I did not switch sooner and only decided to do this because of MS' Windows11 debacle.
I expect the new stuff to last at least ten years. Goodbye MS & thanks for making me love computers.

Disclaimer: I did not get paid by Apple to type this ha ha ha
 
I thought VBS was already enabled by default since Windows 10 20H2, at least for some editions. So are you telling me that until today I could tweak Windows 11 so it can have even worse performance than OOB? Wow.

Modern cybersecurity has become a ridiculous cat-and-mouse game, where the tradeoffs in performance and/or convenience often aren't worth the slightly increased security, that eventually will be broken/circumvented anyways. Use of Hyper-V and VBS in Windows is one such case IMO.

Most developers and managers for big firms like Microsoft, and cybersecurity researchers, also often live in Silicon Valley bubbles and are unable to read the room. Nowadays it's really bad timing for any tradeoff that hurts performance or increases memory usage.

Anyways, as long as the only difference is that now we have another piece of bloat enabled by default that can still be disabled, I don't mind much. But, it's funny how once again Microsoft is behaving like a schizophrenic corporation that appears to have lots of internal struggle between different depts - considering all their recent claims of being concerned about Windows performance and bloat.
 
I keep Hyper-V disabled, which in turn disables VBS. Virtualisation can be used independently of this.

Yes, I consider Hyper-V and other Type-1 hypervisors one of the dumbest things you can use on a home or SOHO machine. Even in smaller organizations, using such an invasive feature is frankly debatable.

I prefer to sip my VMs in Type-2 containers with their own virtual hardware, thank you :-D
 
I happily switched to an M4 Mac Mini and an M5 MacBook Air on Saturday.
I'll probably keep my Windows10 PC's during data migration etc., make my main PC my comics box and put what's now my comics box in storage or pass it on.
MacOS setup is a BLESSING compared to the Windows variety and took about FIVE MINUTES (iPhone sync).
Also, while my Windows10 i9 box is certainly no slouch the M5 MacBook is more than TWICE as fast, and easily the fastest computer I've ever laid hands on.
Apple's more expensive but IMO well worth the money and I'm somewhat sorry I did not switch sooner and only decided to do this because of MS' Windows11 debacle.
I expect the new stuff to last at least ten years. Goodbye MS & thanks for making me love computers.

Disclaimer: I did not get paid by Apple to type this ha ha ha
Back in 2023, I had to use macOS Monterey for three months, on an Intel iMac. It was the first time but I quickly got used. Very pleasant.

Yes, I consider Hyper-V and other Type-1 hypervisors one of the dumbest things you can use on a home or SOHO machine. Even in smaller organizations, using such an invasive feature is frankly debatable.

I prefer to sip my VMs in Type-2 containers with their own virtual hardware, thank you :-D
VMware is a much nicer experience. I only wish I had saved my old XP installation in a VMware-compatible format rather than VHD. Well, the computer still works; perhaps I can.

Microsoft is committed to security in the same way that the US was committed to Afghanistan.
All the spyware we fought off for decades has been refined and built directly into the OS.
To be fair, VBS is an actual attempt at improving security. However, I think Microsoft overdid the implementation, virtualising the OS.
 
"Sacrifice Full performance" - I think MS sacrificed that at the altar of AI Slop and Data Scraping years ago.
 
Back