· via The Verge
Microsoft to auto-enable Windows 11 memory integrity in October, with known gaming performance cost
Microsoft will start enabling Windows 11's memory integrity protection on more eligible devices via quality updates in October, alongside VBS — a change that can cost framerate, especially on older CPUs.

Microsoft is switching memory integrity on for more Windows 11 PCs
Microsoft will begin enabling memory integrity, a kernel-level security feature of Windows 11, on a broader set of eligible hardware through its routine quality updates starting in October, The Verge reports. Where the feature is not already active, the same updates will also switch on Virtualization-based Security (VBS), the underlying virtualization layer that the protection depends on.
Peter Waxman, group program manager at Microsoft, framed the move as part of making Windows "secure by design and secure by default," with the updates turning the protection on for devices that qualify.
What the feature does
Memory integrity restricts the Windows kernel so that only trusted kernel-mode code and drivers can execute. That makes it much harder for malicious software, such as rootkits, to load a tampered driver and burrow into the core of the operating system. The cost is extra validation work on kernel code, plus the overhead of running the VBS layer on machines that have never had it enabled before.
The gaming performance caveat
Microsoft has previously warned that the feature affects game performance, and The Verge notes the impact is uneven: modern CPUs generally show little difference, while older processors can see a more noticeable framerate drop in certain games. For players on aging hardware, the October quality update could therefore translate directly into lost frames.
There is one significant carve-out. According to The Verge, the updates will not re-enable memory integrity on any PC where the user has already deliberately disabled the feature. The automatic rollout only touches machines where the setting has not been switched off by hand.
How to check and control the setting
To see whether memory integrity is active, users can type "Core Isolation" into Windows search and open the matching page in the Windows Security app, where the feature can be toggled on or off. Microsoft's recommendation for anyone who disables it in favour of smoother gaming is to treat the change as temporary: switch the protection back on after finishing a session rather than leaving the system permanently exposed.
Why it matters
The change extends Microsoft's secure-by-default push to a large slice of the Windows 11 installed base. Many users will gain stronger kernel-level defences without doing anything, and VBS will quietly arrive on machines that never ran it before. At the same time, it hard-codes a security-versus-performance trade-off into ordinary monthly patching. Gamers on older CPUs are the group most likely to notice, and for them the practical takeaway is simple: know where the Core Isolation toggle lives, remember that disabling it once is enough to keep it off, and re-enable it if you want the protection back. Because only trusted drivers can run under the feature, systems that rely on unusual or outdated drivers are also worth checking once the update lands.
- #windows-11
- #microsoft
- #security
- #gaming
- #updates