CyberSecurityNews

Microsoft to Expand Memory Integrity Protection Across Windows Devices


Microsoft will begin expanding memory integrity protection across eligible Windows devices in October 2026, automatically enabling a stronger kernel-level security baseline for more users and organizations.

The change is designed to protect Windows from sophisticated attacks that attempt to tamper with critical operating system components, while requiring little or no additional configuration.

Memory Integrity, built on Virtualization-based Security (VBS), uses hardware-assisted virtualization to isolate sensitive Windows components and prevent malicious code from modifying protected kernel areas.

The Windows kernel is a highly privileged part of the operating system. Attackers who gain kernel-level access can turn off security tools, install stealthy drivers, access sensitive data, and maintain persistence on compromised devices.

Microsoft Expands Windows Memory Integrity Protection

Microsoft’s expanded rollout aims to make these attacks more difficult by allowing only trusted kernel-mode code and compatible drivers to run.

Starting with Windows quality updates in October 2026, Microsoft will automatically enable Memory Integrity on compatible devices after readiness checks, enabling VBS if needed to support the security feature.

Microsoft said the readiness process considers hardware support, driver compatibility, and potential performance effects. This approach is intended to avoid enabling the protection on systems that could experience reliability or compatibility problems.

Memory integrity is also known as Hypervisor-Protected Code Integrity, or HVCI. It creates an isolated environment that validates kernel-mode drivers and code before they can execute.

Drivers that do not meet Windows security and compatibility requirements may be blocked, reducing the risk that attackers can abuse vulnerable or malicious drivers to access the kernel.

The move supports Microsoft’s secure-by-design and secure-by-default strategy, which focuses on making stronger protections available without requiring users or administrators to configure every security feature manually.

The company said the rollout will reduce security complexity and help organizations establish a more consistent endpoint protection baseline.

Microsoft said users and administrators will retain control over security settings, with existing policies preserved devices where Memory Integrity is already disabled will not be automatically changed.

Organizations that do not receive automatic enablement can still configure memory integrity manually through Windows Security, Group Policy, mobile device management platforms, and other existing endpoint management tools.

Administrators should review driver compatibility before broad deployment, particularly in environments that use older hardware drivers, specialized peripherals, security products, or legacy business applications. The wider adoption of memory integrity could also support other Windows security improvements.

Microsoft noted that VBS-based protections form part of the foundation for modern capabilities such as hotpatch updates, which can help deliver certain security updates without requiring an immediate device restart.

By enabling memory integrity on more compatible systems, Microsoft is seeking to limit attacks targeting the Windows kernel and critical operating system functions.

The update reflects a broader shift toward hardware-backed protections that make it harder for threat actors to gain persistent, high-privilege control of enterprise and consumer devices.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link