Source: Help Net Security
Author: Anamarija Pogorelec
URL: https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/
ONE SENTENCE SUMMARY:
Starting October 2026, Windows quality updates automatically enable VBS and memory integrity on eligible devices after readiness checks, preserving prior disablement choices.
MAIN POINTS:
- Windows quality updates begin enabling memory integrity automatically starting October 2026.
- Devices lacking Virtualization-based Security will have VBS enabled by those updates.
- Memory integrity allows only trusted kernel-mode code and drivers to run.
- Protection helps prevent attackers from compromising the Windows kernel and core OS functions.
- Deployment occurs via patches, shifting fleet security posture between update cycles.
- Previously disabled memory integrity settings and policies remain unchanged during rollout.
- Organizations can still configure and enable memory integrity using existing management tools.
- Windows evaluates hardware capabilities, compatibility, and performance before enabling protections.
- Microsoft acknowledges readiness checks may miss incompatible or unusual kernel drivers.
- Memory integrity is required to support hotpatch updates that install without rebooting.
TAKEAWAYS:
- Plan for a notable security baseline shift tied directly to routine patching cadence.
- Verify hardware and driver compatibility now to avoid surprises from eligibility gating.
- Keep governance intact: explicit disablement decisions won’t be overridden automatically.
- Treat uncommon kernel-level software as a special risk needing manual validation.
- Enabling memory integrity also unlocks rebootless hotpatch servicing benefits.