Microsoft has announced that beginning in October 2026, Windows quality updates will automatically enable memory integrity protection on eligible devices. This change will also activate Virtualization-based Security (VBS) on machines where it is not already running, as VBS is a prerequisite for memory integrity.
Memory integrity is a security feature designed to prevent attackers from compromising the Windows kernel and gaining control of core operating system functions. It achieves this by ensuring that only trusted kernel-mode code and drivers are allowed to execute. The activation will occur through a standard patch, meaning the security posture of a device fleet can change between update cycles without requiring explicit configuration changes from administrators.
Existing administrator and user policies will remain in effect. This means that devices where memory integrity has been explicitly disabled will not be automatically re-enabled by this rollout. However, for devices where it is not enabled by default, users and organizations can still manually review, configure, and activate the feature using existing Windows security and management tools.
Before enabling the protection, Windows will assess each device for eligibility. This evaluation considers hardware capabilities, compatibility, and performance considerations. This readiness check is why the rollout is limited to "eligible devices." While Microsoft states this evaluation helps identify compatible systems, it does not guarantee that every incompatible kernel driver in an environment will be detected. Organizations running unusual kernel-level software are advised to assume responsibility for potential compatibility issues.
Beyond its role in blocking rootkits and other kernel-level attacks, memory integrity is also a foundational component for hotpatch updates, which allow for the installation of security updates without requiring a system reboot. Devices that remain unprotected by memory integrity will therefore not benefit from this servicing model. For devices that are skipped by the automatic rollout, manual enablement using standard Windows security and management tools remains an option.






