Windows memory integrity switches on automatically for eligible devices in October 2026

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/

ONE SENTENCE SUMMARY:

Starting October 2026, Windows quality updates automatically enable VBS and memory integrity on eligible devices after readiness checks, preserving prior disablement choices.

MAIN POINTS:

  1. Windows quality updates begin enabling memory integrity automatically starting October 2026.
  2. Devices lacking Virtualization-based Security will have VBS enabled by those updates.
  3. Memory integrity allows only trusted kernel-mode code and drivers to run.
  4. Protection helps prevent attackers from compromising the Windows kernel and core OS functions.
  5. Deployment occurs via patches, shifting fleet security posture between update cycles.
  6. Previously disabled memory integrity settings and policies remain unchanged during rollout.
  7. Organizations can still configure and enable memory integrity using existing management tools.
  8. Windows evaluates hardware capabilities, compatibility, and performance before enabling protections.
  9. Microsoft acknowledges readiness checks may miss incompatible or unusual kernel drivers.
  10. Memory integrity is required to support hotpatch updates that install without rebooting.

TAKEAWAYS:

  1. Plan for a notable security baseline shift tied directly to routine patching cadence.
  2. Verify hardware and driver compatibility now to avoid surprises from eligibility gating.
  3. Keep governance intact: explicit disablement decisions won’t be overridden automatically.
  4. Treat uncommon kernel-level software as a special risk needing manual validation.
  5. Enabling memory integrity also unlocks rebootless hotpatch servicing benefits.