Security mitigations

Core isolation and memory integrity (HVCI)

What it protects, the registry values behind the toggle, and Microsoft's note on gaming

Last updated

What does memory integrity protect, and what does it cost?

Memory integrity, also called hypervisor-protected code integrity, is part of Windows' virtualization-based security. It checks that kernel-mode code is signed and trustworthy inside an environment isolated by the Windows hypervisor, which makes the core of the system much harder to compromise. Microsoft notes a possible performance impact in some gaming configurations and describes turning it off while gaming, while warning that doing so reduces protection.

Registry location and values

Enabled

Location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity
Value name
Enabled
Type
REG_DWORD
Default
Depends on hardware and how Windows was installed; on for clean Windows 11 installs on compatible hardware
ValueWhat it does
1Memory integrity on.
0Memory integrity off.

Locked

Location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity
Value name
Locked
Type
REG_DWORD
Default
Not set unless a UEFI lock was configured
ValueWhat it does
0No UEFI lock; the setting can be changed normally.
1Locked with UEFI; turning it off takes more than a registry change.

EnableVirtualizationBasedSecurity

Location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard
Value name
EnableVirtualizationBasedSecurity
Type
REG_DWORD
Default
Depends on configuration
ValueWhat it does
1Turns on virtualization-based security, which memory integrity runs within.

What Windows actually does with this

Virtualization-based security uses the Windows hypervisor to create an isolated region of memory that the normal operating system, kernel included, cannot tamper with. Memory integrity runs the kernel's code integrity checks inside that region, so kernel-mode code and drivers must pass validation there before they run, and kernel memory allocations that could be exploited are restricted. Microsoft notes that processors with hardware support, Intel Kaby Lake or later and AMD Zen 2 or later, run this more efficiently, while older processors rely on an emulation with a bigger performance impact.

What it affects

Protection against malicious or tampered kernel-mode code, and in some gaming configurations, performance. It also affects drivers: Microsoft notes that drivers incompatible with it can malfunction, and in rare cases stop Windows starting.

Is it worth changing?

Leave it on unless you have measured a difference in the games you play. Microsoft's own guidance acknowledges a possible performance impact in some scenarios and configurations and describes turning memory integrity and the Virtual Machine Platform off while gaming and on again afterwards, but it also warns that this reduces protection. That makes it a deliberate, tested and temporary change, not a permanent tweak, and never something to switch off simply because an optimizer suggested it.

What can go wrong

Turning it off removes a layer of protection against kernel-level malware, which is the entire purpose of the feature. Turning it on can expose incompatible drivers, which Microsoft says may malfunction or, rarely, cause a failure to start. If memory integrity was enabled with a UEFI lock, the registry value alone will not turn it off.

How to undo it

Windows Security → Device security → Core isolation details → Memory integrity, then restart. If Windows will not start after it was enabled, Microsoft's recovery step is to open a command prompt in the Windows Recovery Environment, set the Enabled value to 0 under the HypervisorEnforcedCodeIntegrity key, and restart.

Create a System Restore Point before editing the registry. Every setting on this page is reversible, but a restore point is the difference between undoing one change and reinstalling Windows.

Which Windows versions this applies to

Windows 10 and Windows 11. On Windows 11 it is on by default for clean installs on compatible hardware, and from version 22H2 Windows Security shows a warning when it is off.

Core isolation and memory integrity (HVCI): common questions

How do I check whether memory integrity is running?

Open Windows Security, then Device security and Core isolation details. For more detail, System Information (msinfo32) lists the virtualization-based security services that are running under System Summary.

Why can't I turn memory integrity on?

A common reason is an incompatible driver, which prevents it being enabled until that driver is updated or removed. Virtualization also needs to be enabled in the PC's firmware for virtualization-based security to run.

Does memory integrity lower frame rate in games?

Microsoft notes a possible performance impact in some gaming scenarios and configurations, and older processors without hardware support are affected more. The only reliable answer for your PC is to compare frame times with it on and with it off.

Is it safe to turn off memory integrity?

Windows supports turning it off, but doing so removes protection against kernel-level malware. If you switch it off for gaming, turn it back on afterwards, and avoid installing unfamiliar drivers or software while it is off.

Sources

Related settings

Guides that cover this setting

Every change JINSHI PC Tweaks can make is listed on the complete tweak list, and the product itself is described on PC Tweaks for gaming.


If you would rather not do it by hand

JINSHI Tweaks: all four apps

£29.99one-time

Get all four apps

Every change can be reversed on its own. No subscription, nothing to renew.

Get all four — £29.99