Cyber Security News

Microsoft to Expand Memory Integrity Protection Across Windows Devices

Microsoft will begin expanding memory integrity protection across eligible Windows devices in October 2026, automatically enabling a stronger kernel-level security baseline for more users and organizations.

The change is designed to protect Windows from sophisticated attacks that attempt to tamper with critical operating system components, while requiring little or no additional configuration.

Memory Integrity, built on Virtualization-based Security (VBS), uses hardware-assisted virtualization to isolate sensitive Windows components and prevent malicious code from modifying protected kernel areas.

The Windows kernel is a highly privileged part of the operating system. Attackers who gain kernel-level access can turn off security tools, install stealthy drivers, access sensitive data, and maintain persistence on compromised devices.

Microsoft Expands Windows Memory Integrity Protection

Microsoft’s expanded rollout aims to make these attacks more difficult by allowing only trusted kernel-mode code and compatible drivers to run.

Starting with Windows quality updates in October 2026, Microsoft will automatically enable Memory Integrity on compatible devices after readiness checks, enabling VBS if needed to support the security feature.

Microsoft said the readiness process considers hardware support, driver compatibility, and potential performance effects. This approach is intended to avoid enabling the protection on systems that could experience reliability or compatibility problems.

Memory integrity is also known as Hypervisor-Protected Code Integrity, or HVCI. It creates an isolated environment that validates kernel-mode drivers and code before they can execute.

Drivers that do not meet Windows security and compatibility requirements may be blocked, reducing the risk that attackers can abuse vulnerable or malicious drivers to access the kernel.

The move supports Microsoft’s secure-by-design and secure-by-default strategy, which focuses on making stronger protections available without requiring users or administrators to configure every security feature manually.

The company said the rollout will reduce security complexity and help organizations establish a more consistent endpoint protection baseline.

Microsoft said users and administrators will retain control over security settings, with existing policies preserved devices where Memory Integrity is already disabled will not be automatically changed.

Organizations that do not receive automatic enablement can still configure memory integrity manually through Windows Security, Group Policy, mobile device management platforms, and other existing endpoint management tools.

Administrators should review driver compatibility before broad deployment, particularly in environments that use older hardware drivers, specialized peripherals, security products, or legacy business applications. The wider adoption of memory integrity could also support other Windows security improvements.

Microsoft noted that VBS-based protections form part of the foundation for modern capabilities such as hotpatch updates, which can help deliver certain security updates without requiring an immediate device restart.

By enabling memory integrity on more compatible systems, Microsoft is seeking to limit attacks targeting the Windows kernel and critical operating system functions.

The update reflects a broader shift toward hardware-backed protections that make it harder for threat actors to gain persistent, high-privilege control of enterprise and consumer devices.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago