Security mitigations
Core isolation and memory integrity (HVCI)
What it protects, the registry values behind the toggle, and Microsoft's note on gaming
Last updated
What does memory integrity protect, and what does it cost?
Memory integrity, also called hypervisor-protected code integrity, is part of Windows' virtualization-based security. It checks that kernel-mode code is signed and trustworthy inside an environment isolated by the Windows hypervisor, which makes the core of the system much harder to compromise. Microsoft notes a possible performance impact in some gaming configurations and describes turning it off while gaming, while warning that doing so reduces protection.
Registry location and values
Enabled
- Location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity- Value name
Enabled- Type
REG_DWORD- Default
- Depends on hardware and how Windows was installed; on for clean Windows 11 installs on compatible hardware
| Value | What it does |
|---|---|
1 | Memory integrity on. |
0 | Memory integrity off. |
Locked
- Location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity- Value name
Locked- Type
REG_DWORD- Default
- Not set unless a UEFI lock was configured
| Value | What it does |
|---|---|
0 | No UEFI lock; the setting can be changed normally. |
1 | Locked with UEFI; turning it off takes more than a registry change. |
EnableVirtualizationBasedSecurity
- Location
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard- Value name
EnableVirtualizationBasedSecurity- Type
REG_DWORD- Default
- Depends on configuration
| Value | What it does |
|---|---|
1 | Turns on virtualization-based security, which memory integrity runs within. |
What Windows actually does with this
Virtualization-based security uses the Windows hypervisor to create an isolated region of memory that the normal operating system, kernel included, cannot tamper with. Memory integrity runs the kernel's code integrity checks inside that region, so kernel-mode code and drivers must pass validation there before they run, and kernel memory allocations that could be exploited are restricted. Microsoft notes that processors with hardware support, Intel Kaby Lake or later and AMD Zen 2 or later, run this more efficiently, while older processors rely on an emulation with a bigger performance impact.
What it affects
Protection against malicious or tampered kernel-mode code, and in some gaming configurations, performance. It also affects drivers: Microsoft notes that drivers incompatible with it can malfunction, and in rare cases stop Windows starting.
Is it worth changing?
Leave it on unless you have measured a difference in the games you play. Microsoft's own guidance acknowledges a possible performance impact in some scenarios and configurations and describes turning memory integrity and the Virtual Machine Platform off while gaming and on again afterwards, but it also warns that this reduces protection. That makes it a deliberate, tested and temporary change, not a permanent tweak, and never something to switch off simply because an optimizer suggested it.
What can go wrong
Turning it off removes a layer of protection against kernel-level malware, which is the entire purpose of the feature. Turning it on can expose incompatible drivers, which Microsoft says may malfunction or, rarely, cause a failure to start. If memory integrity was enabled with a UEFI lock, the registry value alone will not turn it off.
How to undo it
Windows Security → Device security → Core isolation details → Memory integrity, then restart. If Windows will not start after it was enabled, Microsoft's recovery step is to open a command prompt in the Windows Recovery Environment, set the Enabled value to 0 under the HypervisorEnforcedCodeIntegrity key, and restart.
Create a System Restore Point before editing the registry. Every setting on this page is reversible, but a restore point is the difference between undoing one change and reinstalling Windows.
Which Windows versions this applies to
Windows 10 and Windows 11. On Windows 11 it is on by default for clean installs on compatible hardware, and from version 22H2 Windows Security shows a warning when it is off.
Core isolation and memory integrity (HVCI): common questions
How do I check whether memory integrity is running?
Open Windows Security, then Device security and Core isolation details. For more detail, System Information (msinfo32) lists the virtualization-based security services that are running under System Summary.
Why can't I turn memory integrity on?
A common reason is an incompatible driver, which prevents it being enabled until that driver is updated or removed. Virtualization also needs to be enabled in the PC's firmware for virtualization-based security to run.
Does memory integrity lower frame rate in games?
Microsoft notes a possible performance impact in some gaming scenarios and configurations, and older processors without hardware support are affected more. The only reliable answer for your PC is to compare frame times with it on and with it off.
Is it safe to turn off memory integrity?
Windows supports turning it off, but doing so removes protection against kernel-level malware. If you switch it off for gaming, turn it back on afterwards, and avoid installing unfamiliar drivers or software while it is off.
Sources
Related settings
Guides that cover this setting
Every change JINSHI PC Tweaks can make is listed on the complete tweak list, and the product itself is described on PC Tweaks for gaming.
If you would rather not do it by hand
JINSHI Tweaks: all four apps
£29.99one-time
Get all four appsEvery change can be reversed on its own. No subscription, nothing to renew.