Windows Is Switching Memory Integrity On By Itself This Month. If an Old Driver Is in the Way, Here's What You'll See.
October 2, 2026
There is no new version of Windows and nothing to click: the setting rides in on a monthly update, a few machines at a time. For most people nothing changes. For the ones where an old driver is in the way, here is the message you will get and the order to work through it.
Over the next few weeks, a Windows security setting called memory integrity is going to switch itself on, on machines where it has been off for years. Microsoft announced it in a single sentence on September 1, 2026: "Beginning in October 2026, Windows quality updates will start enabling memory integrity on more eligible Windows devices." There is no new version of Windows involved and nothing for you to click. It arrives inside the ordinary monthly update.
For the overwhelming majority of people this will be completely invisible — the setting turns on, the machine carries on, and the PC is genuinely better protected than it was the week before. But on a small number of computers one specific thing happens instead: something stops working. A scanner, a label printer, an old USB adapter, a utility that came bundled with a piece of hardware. And with it comes a notification that says "A driver can't load on this device."
That notification reads exactly like a malware warning, which is why people panic at it and why it is a gift to scammers. It is not a malware warning, and Microsoft says so in plain words on its own support page. That is worth having in front of you before you start searching, so we will start there.
First, the sentence that calms everyone down
Microsoft's support page for this exact message explains the cause without drama: "You are receiving this message because the Memory Integrity setting in Windows Security is preventing a driver from loading on your device." Further down the same page, it addresses the fear directly: "Though the driver has a minor vulnerability that's preventing it from loading, it's most likely not malicious in any way."
Read that again, because it is the opposite of what the message feels like. Windows is not telling you that something infected your computer. It is telling you that a piece of software that talks directly to the heart of Windows was written to older rules, and that Windows has decided — as of this month, on its own — to stop giving that kind of software the benefit of the doubt. The driver is probably just old.
You may see it in a slightly different wrapper, too. Microsoft's own note on the subject covers that case: "If you encounter a banner titled Program Compatibility Assistant with a message indicating that a driver cannot load, or that a security setting is preventing a driver from loading, check for updated drivers via Windows Update or through Device Manager." Same underlying cause, different box on the screen.
What memory integrity actually is
Microsoft's plain-English description is the one worth using: memory integrity, "also known as Hypervisor-protected Code Integrity (HVCI) is a Windows security feature that makes it difficult for malicious programs to use low-level drivers to hijack your PC."
The analogy in Microsoft's own documentation is a security guard in a locked booth. Code that wants to run deep inside Windows has to be handed through to that booth to be checked before Windows will run it, and because the booth is sealed off using hardware virtualization, an attacker cannot lean over and interfere with the guard. Without it, Microsoft writes, the guard "stands right out in the open." The practical effect, in the words of the announcement, is that only "trusted kernel-mode code and drivers" get to run.
You will find it in Windows Security under Device security, then Core isolation details. If someone has told you to check "core isolation," that is the same page. If you have read older documentation calling this HVCI, hypervisor-enforced code integrity, or Device Guard, those are all the same feature under previous names — Microsoft notes that the Device Guard name now survives only as the place the settings live in Group Policy and the registry.
Why it is turning on now — and whose machines it is turning on for
The official notice in Microsoft's Windows message center, dated September 1, 2026, is short and worth quoting almost in full, because every clause answers a question people are asking: "Beginning in October 2026, Windows quality updates will start enabling memory integrity on more eligible Windows devices. On some devices, this change will also enable virtualization-based security (VBS). The rollout will occur gradually, so the change might not reach all eligible devices at the same time."
Windows checks your machine over before it does this. Microsoft: "Before enabling it, Windows evaluates device readiness based on factors such as hardware capabilities, compatibility, performance considerations, Windows 11 system requirements, and recommended built-in protections."
Here is the part that tells you whether you are even in scope. Memory integrity has been turned on by default on clean installs of Windows 11 for years already, on hardware that qualifies. So the machines where this October is a change are mostly the ones that did not get a clean install — PCs that were upgraded in place and have carried the same Windows installation forward, which in Southern California means an awful lot of the machines that were pushed from Windows 10 to Windows 11 around the October 2025 end-of-support deadline. If your PC came out of the box with Windows 11 on it, odds are this setting has been on the whole time and this month is a non-event for you.
And one sentence settles the question we expect to be asked most: "Devices on which memory integrity was previously disabled will not be automatically changed by this rollout." If you — or whoever looks after your computer — deliberately turned this off at some point, Microsoft is not overruling that decision. The blog post announcing the change says the same thing: "Existing administrator and user decisions and policies remain in effect."
Do also take the word "gradually" literally. Two near-identical computers in the same house or the same office can be weeks apart on this. If one of them suddenly cannot see the scanner and the other is fine, that is not a mystery — it is the rollout.
What actually breaks, and why it is almost always something old
The reassuring context first. Being compatible with memory integrity is not a new requirement that drivers are being ambushed with — it is a decade old. In Microsoft's words: "Although compatibility with memory integrity has been a requirement for all drivers since the Windows 10 Anniversary Update (1607), some applications and hardware device drivers may still be incompatible." Microsoft also requires a specific test to pass — the "HyperVisor Code Integrity Readiness Test" — before a driver can be approved for Microsoft signing.
So a driver written and signed to current rules sails through this. What trips over it is old code: a driver from the early 2010s for a device you have had forever, or a utility nobody has rebuilt since.
Microsoft publishes the categories where it has actually seen trouble: "Anti-cheat solutions with gaming," "3rd party input methods," and "3rd party banking password protection." Translated into the households and small offices we work in, that is a gaming PC in the family, a tool for typing in a language other than English, and those security add-ons that some banks ask you to install before you can log in. To that list, experience adds a fourth that is not exotic at all: a driver for a gadget you no longer even own, left behind years ago because uninstalling hardware drivers is something almost nobody does.
In rare cases it is more serious than a dead peripheral. Microsoft: this incompatibility "can cause devices or software to malfunction and in rare cases may result in a boot failure (blue screen)."
Windows has a safety net for the frightening version of this
Worth knowing before you worry about it: Microsoft anticipated the nightmare case where the blocked driver is one Windows needs in order to start at all. From its driver-compatibility documentation: "We worked hard to mitigate impacted experiences, so if an incompatibility exists for a boot-critical driver, memory integrity protection will be silently turned off if it had been auto-enabled."
The mechanism behind that sentence is exactly what you would want: if the system crashes while starting up, the machine turns memory integrity back off by itself. Microsoft's documentation notes that this self-rescue is only available for the first few restarts after the setting was enabled, which is sensible — it is there to catch a bad enablement, not to switch the protection off forever the next time the PC has an unrelated bad day.
There is a useful corollary. If you go and look at Core isolation after an update and find memory integrity switched off, that is not necessarily a failed update or a sign something is wrong. On some machines that is the safety net having done its job.
If a PC does end up unable to start and does not rescue itself, there is a documented recovery route through the Windows Recovery Environment, with one trap in it: if memory integrity was turned on with what Microsoft calls a UEFI lock, you have to turn off Secure Boot in the firmware before that recovery will work. That is the point to stop guessing and get someone to look at it — a machine that will not boot is a bad place to learn by experiment, and it is a routine visit for us.
How to find out which driver is the problem
Go to Windows Security, then Device security, then Core isolation details. On Windows 11 the longer path is Start, then Settings, then Privacy & security, then Windows Security, then Device Security; on Windows 10 the same page sits under Update & Security instead. When memory integrity has objected to something, Windows will name it there.
Then set your expectations, because Microsoft is unusually candid about the limits of what it can tell you: "The driver name and company name that appear in the notification are the only reliable pieces of information that we have been able to gather about the driver."
That is the whole difficulty in one sentence. Windows can tell you that a file like some cryptic eight-character name ending in .sys is the problem; it cannot tell you that the file is the scanner half of the all-in-one printer in the back office. Working back from a driver filename to the actual object on your desk is the part people get stuck on, and it is most of what we end up doing on these jobs. The company name is usually the more useful of the two clues — a manufacturer you recognise narrows it down faster than the filename will.
If you want the underlying record rather than the summary, Windows keeps one. Microsoft points to Event Viewer, under Applications and Services Logs, then Microsoft, then Windows, then CodeIntegrity, then Operational, and notes that "memory integrity compatibility events have EventID=3087."
What to do about it, in order
Start with an updated driver, which fixes this outright when it exists. Microsoft's first suggestion is to "see if an updated and compatible driver is available through Windows Update or from the driver manufacturer." Check Windows Update first because it costs nothing, then go to the manufacturer's own support page for your exact model. Do not use a driver-updater utility you found through an ad to do this; that is its own category of problem, and this is a situation where downloading a driver from a stranger is a genuinely bad idea.
Second, consider whether you still use the thing at all. Microsoft's advice for when no fixed driver exists is blunt and often the right answer: "If they don't have compatible driver available, you might be able to remove the device or app that uses that incompatible driver." If the blocked driver belongs to a printer you replaced in 2019, removing the leftover software is not a compromise — it is tidying up, and it gets you the security setting and a cleaner machine at once.
Third, if the driver came bundled with an application, update the application and not just the driver. Microsoft specifically asks you to try this before giving up: "we advise that you check for updates for the specific app and version encountering the issue before turning off memory integrity protection."
Fourth, if there is no update anywhere, it is reasonable to go and ask. Microsoft suggests it too: "If an updated driver is unavailable from the driver manufacturer, it might be a good idea to contact them and inquire whether a fix is coming soon." For a business-grade scanner or a piece of shop equipment, a vendor who hears this from enough customers sometimes ships the fix.
Only then should turning memory integrity off be on the table — and when it genuinely is the answer, it is the answer. A dental office whose X-ray sensor only talks to a driver last updated in 2016 is not going to replace a five-figure sensor over a Windows setting. But make it a decision rather than a reflex, because you are giving up a real defence, and consider whether the affected machine can be the one that does not handle the banking.
If you do turn it off, know exactly what you are giving up
Microsoft's warning is specific about one class of machine: "Turning off Memory Integrity on a Secured-core PC takes the device out of a Secured-core state." Many business laptops bought in the last few years are Secured-core PCs, and the Device security page will tell you if yours is.
There is also a knock-on effect people do not expect. The Microsoft vulnerable driver blocklist — a list of drivers that, in Microsoft's description, "have known security vulnerabilities, have been signed with certificates used to sign malware, or that circumvent the Windows Security Model" — is tied to this. Microsoft: "If you have memory integrity, Smart App Control, or Windows S mode on, the vulnerable driver blocklist will be on too." Having memory integrity on is one of the things that brings that list along with it.
And expect to be nagged. Since Windows 11 version 22H2, Windows Security shows a warning when memory integrity is off, and that warning also appears on the Windows Security icon in the taskbar and in the notification centre. It can be dismissed from within Windows Security, which is worth doing deliberately — otherwise you will have a permanent red badge and no memory of why, and a red security badge you have learned to ignore is a bad habit to teach yourself.
The other half of Microsoft's warning is the honest one about simply doing nothing: if you keep using the device without sorting out the driver, "you might discover that the functionality the driver supports does not work any longer, which could have consequences ranging from negligible to severe." A dead driver for an old webcam is negligible. A dead driver for the thing that reads your backup tapes is not.
Will this make my computer slower?
On an older machine it can, and there is a concrete reason rather than a vague one. Memory integrity leans on specific processor features, and Microsoft spells out the dividing line: it "works better with Intel Kabylake and higher processors with Mode-Based Execution Control, and AMD Zen 2 and higher processors with Guest Mode Execute Trap capabilities. Older processors rely on an emulation of these features, called Restricted User Mode, and will have a bigger impact on performance."
In other words, on a reasonably modern chip the protection is largely handled in hardware and the cost is small. On an older one, Windows has to emulate the missing pieces, and emulation is where the noticeable slowdown comes from. That is the real explanation behind the gaming-performance headlines this change attracted.
This is also why "performance considerations" appears in Microsoft's list of things Windows weighs up before switching the setting on — the machines where it would hurt most are the ones it is supposed to skip. But if your PC became sluggish right after an October update and you find memory integrity newly switched on, you are not imagining a connection, and that is a fair thing to weigh. It is one of the things we check on a machine that is slow everywhere rather than just slow to start.
The hardware floor, if you want to know whether you are even eligible
The bar Microsoft publishes for turning memory integrity on by default is modest: an Intel 8th-generation processor or later (as of Windows 11 version 22H2), and a minimum of 8GB of memory on a 64-bit machine, with memory integrity-compatible drivers installed. There is also one specific carve-out in the documentation that is easy to miss: "Intel 11th generation Core desktop processors are not included in current default enablement logic."
One more prerequisite catches people out, usually on self-built or older desktops: "To use memory integrity, you must have hardware virtualization enabled in your system's UEFI or BIOS." If virtualization was switched off in the firmware years ago, the setting will not turn on at all, and the reason is not in Windows.
If that 8th-generation floor sounds familiar, it is roughly the same territory as Windows 11's own supported-processor list, and Microsoft includes "Windows 11 system requirements" among the readiness factors. If you have been through that argument already with your PC, our guide to the TPM and Secure Boot errors covers that side of it.
If you run a small business, do this now rather than in three weeks
The gradual rollout is the thing to plan around. One workstation can get this weeks before the identical one beside it, so the failure you are likely to meet is the confusing kind: the label printer works at one desk and not at the other, with nothing obviously different between them.
Spend ten minutes making a list of the equipment in your office that is not a mouse, a keyboard or a monitor — the scanner, the label and receipt printers, the card reader, the time clock, the signature pad, the dongle that licenses an old program, and anything at all that came with a vendor CD. Those are your candidates. For each one, check the vendor's support page for a current Windows 11 driver. Finding out today that a vendor went quiet in 2017 is a scheduling problem; finding out on a Monday morning when the invoices need printing is an emergency.
What we would not do is pre-emptively switch memory integrity off across the office to avoid the whole subject. That opts those machines out of a real protection for good — remember that devices where it was previously disabled are left alone by this rollout — and it trades a known, manageable risk for an unknown one. Check the short list instead, and turn it off only on the specific machine that genuinely needs it.
One more thing: this is a scammer's favourite month
A scary notification about drivers, in a month when the technology press is full of stories about Windows changing a security setting, is exactly the raw material fake-support pages are built from. Expect pop-ups and search ads offering to "fix your driver error," and expect some of them to look convincing.
The real notification behaves nothing like that. It does not give you a phone number. It does not ask you to call anybody, pay anybody, paste a command, or let a stranger connect to your computer. It names a driver and a company and then it stops talking. Anything that goes further than that is not Windows.
If what you are looking at asks you to ring a number or run a command you were given, close it and read our guide to the fake Windows update screen instead — that is a different problem with a different answer, and it is a far more expensive one to get wrong.
Bottom line
Memory integrity turning on is good news that will arrive quietly for nearly everyone. If it arrives loudly for you, the message is not a virus warning, the cause is almost certainly a driver older than the rules it is being judged by, and the fix order is: current driver from the manufacturer, then remove the software if you no longer use the hardware, then update the app it came with, then ask the vendor — and only then consider switching the protection off, on that one machine, on purpose.
If you get stuck at the step everybody gets stuck at — Windows has named a driver file and you have no idea which device it belongs to — that is a short job for us, and a much better use of an afternoon than guessing. We work on Windows desktops and laptops across the Los Angeles, Orange County, Ventura and Inland Empire areas, in homes and small offices, and we are happy to sort out which of your peripherals is the holdout and whether it has a current driver at all.
Keep reading
- Printer Says "Driver Is Unavailable"? What Windows Changed in 2026, and What Actually Fixes It
- That "Windows Update" Screen Telling You to Paste a Command Is a Scam
- Windows 11 Slow to Start? Why Boot Takes Minutes — and How to Speed It Up
- This PC Can't Run Windows 11? How to Fix the TPM and Secure Boot Errors
- Can't Get Online? A Corrupted Network Driver Might Be Why
- Windows Update Stuck Downloading or Won't Install? How to Unstick It
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020