Windows memory integrity switches on automatically for eligible devices in October 2026

Starting in October 2026, Windows will automatically enable memory integrity protection on eligible devices to prevent unauthorized kernel-mode code execution. This security update will also enable Virtualization-based Security (VBS) on systems where it is not currently active.
Why it matters
This change significantly hardens the Windows kernel against rootkits and malware, though it may impact users running specialized or legacy kernel-level drivers.
Windows memory integrity switches on automatically for eligible devices in October 2026 Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too.
Memory integrity is the layer that allows only trusted kernel-mode code and drivers to run, which is how it stops an attacker who is trying to compromise the Windows kernel and take control of core operating system functions.
The change arrives as a patch, so the security posture of a fleet can move between one update cycle and the next without anyone filing a change request.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in