Microsoft Activates Kernel Security Shield for Millions of Windows 11 PCs
Microsoft is set to auto-enable a major kernel security feature called Memory Integrity on Windows 11 PCs starting from October 2026. This change will come through the Patch Tuesday update on October 13, and it's estimated that millions of eligible devices will be affected.
Memory Integrity, also known as Hypervisor-protected Code Integrity (HVCI), creates an isolated environment using CPU virtualization hardware to block malicious code from reaching the kernel. This feature has been available for years but was not enabled by default on many PCs that qualified for it.
The reason for this change is the increased pressure on Windows security due to AI-assisted vulnerability research, which can now identify kernel-level bugs in Windows more quickly than before. Turning on Memory Integrity is a cheap way to close off a class of attacks without waiting for a slower fix elsewhere in the OS.