What memory integrity actually does
In plain Windows, any driver that loads runs with full kernel privileges — and fake or trojaned drivers are a favorite way for malware to get that deep, because antivirus running above the kernel cannot easily police what happens inside it. Memory integrity, technically called Hypervisor-protected Code Integrity (HVCI), flips the arrangement: the CPU’s virtualization features start a small hypervisor underneath Windows, and the checks that decide which code may enter the kernel run inside that protected layer instead of inside the kernel itself. A driver without a valid signature simply never gets in.
The feature is part of Virtualization-Based Security (VBS) and has shipped since Windows 10 version 1803, free in every edition including Home. Since late 2022 Microsoft enables it by default on many new Windows 11 PCs with capable hardware, so it may already be on without you ever touching it — checking takes thirty seconds and is worth it.
- Blocks unsigned, tampered and known-malicious drivers from entering the kernel — the entry route of modern bootkits
- Runs on the CPU’s VT-x / AMD-V virtualization; a TPM is not required to turn the switch on
- Available in Windows 10 (1803 and later) and Windows 11, including Home editions
- On roughly 8th-gen Intel and Ryzen 2000+ CPUs the overhead is negligible; older CPUs may lose a few percent
- Enabled by default on many new Windows 11 installs since 2022 — verify rather than assume
How to enable it, step by step
Open Settings → Privacy & security → Windows Security, click Open Windows Security, then go to Device security → Core isolation settings, and turn on the Memory integrity toggle; approve the UAC prompt if one appears. If Windows immediately warns about incompatible drivers, deal with them first — see the next section — because the switch will refuse to stay on until they are updated or removed. Save your work and restart when asked: the hypervisor builds its protected layer during boot, so the change only fully applies after a reboot.
After restarting, verify that the setting stuck: reopen Core isolation settings and confirm the toggle is still on, then press Win+R, type msinfo32 and look for the “Virtualization-based security” line — it should read “Running”. If it says “Not enabled”, the most common reasons are virtualization disabled in the BIOS/UEFI or a machine still booted in legacy BIOS mode, and fixing either usually brings the switch to life.
When it won’t turn on: incompatible drivers
The number-one blocker is an old driver on the system, and Windows names it: the Core isolation page shows a “Review incompatible drivers” link that lists exactly which device and file are in the way. Usual suspects are aging graphics and audio drivers, old virtualization software and outdated anti-cheat components. The fix is to update the device through Windows Update → Advanced options → Optional updates or at the manufacturer’s site, or to uninstall the program that dragged the stale driver along. Reboot, and the list is usually empty.
In the rare case where a PC blue-screens after enabling memory integrity, boot into Safe Mode (hold the power button during a failed start until WinRE appears, then Troubleshoot → Advanced options → Startup Settings) and switch the toggle back off from there. Do not force the feature on through registry edits on hardware that refuses it — the refusal is the system telling you a driver or firmware is not ready, and overriding it trades stability for a checkbox. On modern CPUs the measurable performance cost is essentially zero; if games lose frames after enabling it, suspect an outdated graphics driver long before the security layer.
Questions and Answers
Does memory integrity slow down games?
On modern CPUs — roughly 8th-gen Intel and Ryzen 2000 and newer — the impact is within measurement noise. If frame rates drop measurably, an outdated graphics driver is the more likely culprit, and it would also show up in the incompatible-drivers list.
Why can’t I turn on memory integrity — it mentions incompatible drivers?
An old driver is blocking it. Open “Review incompatible drivers” on the Core isolation page, update that device through Optional updates or the manufacturer, or uninstall the program that shipped the stale driver, then reboot and try again.
What is the difference between memory integrity and VBS?
Memory integrity (HVCI) is the user-facing switch for one part of Virtualization-Based Security. VBS is the umbrella technology that can also isolate credentials and kernel memory; turning on memory integrity brings the VBS hypervisor with it.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]