What and why
Beginning in October 2026, Windows quality updates will start enabling memory integrity on more eligible Windows devices. On some devices, this change will also enable virtualization-based security (VBS).
Memory integrity helps protect critical parts of Windows from tampering by allowing only trusted kernel-mode code and drivers to run. Before enabling the protection, Windows evaluates device readiness based on hardware capabilities, compatibility, performance considerations, Windows 11 system requirements, and recommended built-in protections.
Rollout schedule
The gradual rollout begins in October 2026. It might not reach all eligible devices at the same time.
Impact on your organization
Eligible devices might have memory integrity, and in some cases VBS enabled, automatically through Windows quality updates.
Existing administrator and user choices and policies remain in effect. This rollout won't automatically change devices on which you explicitly disable memory integrity.
Action required/recommendations
Organizations should:
• Review existing memory integrity and VBS policies and device configurations.
• Review Expanding memory integrity protection across Windows devices for information about the rollout.
• See Enable memory integrity for configuration and management guidance.
Compliance considerations
No compliance considerations are identified. Review as appropriate for your organization.