Memory integrity, also called Hypervisor-protected Code Integrity (HVCI), is a Windows security feature under Core isolation that uses hardware virtualization to make it harder for malicious low-level drivers to hijack a PC. To manage it in Windows 11, open Windows Security > Device security > Core isolation details and use the Memory integrity switch. Keep it on when possible; if an incompatible driver is blocking it, first look for a compatible update from Windows Update or the device manufacturer.
Core isolation is the feature area; Memory integrity is one setting within it. The controls shown there can vary by Windows version and installed hardware.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Windows 11 All-in-One For Dummies, 2nd Edition | $27.49 | Buy on Amazon |
How to enable Memory integrity in Windows 11
- Open Windows Security. You can find it by opening Start and searching for Windows Security.
- Select Device security.
- Under Core isolation, select Core isolation details.
- Turn the Memory integrity switch On.
- Restart Windows if prompted.
Memory integrity requires hardware virtualization to be enabled in UEFI or BIOS. If Windows reports that virtualization is unavailable, consult your PC manufacturer’s instructions for enabling hardware virtualization in firmware. If Windows identifies an incompatible driver, update or remove the software or device that uses it before trying again. Microsoft’s Device Security guidance explains the feature and its requirements.
How to disable Memory integrity
Turning Memory integrity off reduces its additional protection against vulnerable kernel-level drivers. On a Secured-core PC, disabling it takes the device out of its Secured-core state. If you need a driver to work, first check for a compatible update; turning the setting off does not guarantee the device or application will function correctly.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Open Windows Security.
- Go to Device security > Core isolation > Core isolation details.
- Set Memory integrity to Off.
- Restart the PC for the change to take effect.
Use this as a troubleshooting choice rather than a routine fix. Microsoft describes the steps and warns about the security and compatibility tradeoffs in its guidance on a driver that can’t load on a device.
Windows 11 Settings path
You can also reach Windows Security through Settings:
Start > Settings > Privacy & security > Windows Security > Device security > Core isolation > Core isolation details
The path Settings > Update & Security > Windows Security belongs to Windows 10, not the current Windows 11 Settings path.
What Core isolation does
Core isolation uses virtualization-based security to help isolate Windows security processes from the normal operating system environment. Memory integrity uses hardware virtualization to isolate code-integrity checks, making it harder for malicious low-level drivers to take over the PC.
Depending on Windows version and installed hardware, the Core isolation page may show other settings. These are separate features; Core isolation is not necessarily one master switch, and the absence of a particular option does not automatically indicate a problem.
Hardware and firmware requirements
Hardware virtualization must be enabled in UEFI or BIOS for Memory integrity to work. The setting’s name and location vary by PC manufacturer, so follow the manufacturer’s firmware instructions rather than changing unrelated options. Secure Boot is a separate startup-security feature; it is not the same setting as Memory integrity.
Fix “Memory integrity can’t be enabled”
An incompatible device driver can prevent Memory integrity from turning on. Windows may display an Incompatible drivers link or a warning naming the driver.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Record the displayed driver name and company name.
- Check Settings > Windows Update for available updates, including offered driver updates.
- Check the device or driver manufacturer’s support channel for a compatible update.
- If no compatible driver is available, consider removing the device or application that depends on it, if appropriate.
- Restart Windows and try enabling Memory integrity again.
An incompatible-driver warning does not mean the driver is malware. Microsoft says a reported driver may have a vulnerability that prevents it from loading and is most likely not malicious.
Installing a device or application with an incompatible driver after enabling Memory integrity can also cause a warning. In that case, look for a compatible driver or remove the software that installed it.
Fix “A driver can’t load on this device”
This notification can mean that Windows is blocking a low-level driver because of Memory integrity or another security setting. The affected device or application may stop working even while Windows continues to run.
Use the driver and company names in the notification to look for a compatible update through Windows Update or the device manufacturer’s support channel. If no compatible driver is available, Microsoft says you can remove the device or application, or choose to disable Memory integrity. Disabling the feature may allow the driver to load, but does not guarantee that the device or application will work correctly; it also reduces protection. On a Secured-core PC, switching it off ends the device’s Secured-core state.
What to do if the Core isolation page is missing
The available Core isolation features vary with Windows version and installed hardware. If the page or a particular toggle is absent:
- Install pending Windows updates.
- Open Windows Security and select Device security.
- Check your PC manufacturer’s support documentation for firmware and hardware support information.
- Use an administrator account if Windows asks for permission to change the setting.
Do not assume that a missing option can be safely added with an undocumented Registry, PowerShell, or boot-configuration command. Use the Windows Security controls.
Related protection settings
Windows’ vulnerable driver blocklist covers drivers with known security vulnerabilities, drivers signed with certificates used to sign malware, and drivers that circumvent the Windows Security Model. Microsoft says the blocklist is on when Memory integrity, Smart App Control, or Windows S mode is on. If a driver is blocked, first look for a compatible update through Windows Update or the device manufacturer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Should you leave Memory integrity enabled?
For ordinary use, keep Memory integrity enabled. If a necessary device or application is incompatible, first look for an updated compatible driver. Consider disabling the feature only if you need to troubleshoot and understand the tradeoff; it may not restore the device’s functionality, and on a Secured-core PC it ends the Secured-core state.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute| Choice | Security and compatibility | What to expect |
|---|---|---|
| Keep Memory integrity on | Preserves its additional code-integrity protection. | Update the incompatible driver or remove the device or application that depends on it. |
| Turn Memory integrity off | Reduces that protection. | Requires a restart; the driver or device may still fail, and a Secured-core PC leaves its Secured-core state. |
FAQ
Is Core isolation the same as Memory integrity?
No. Core isolation is the Windows Security area containing security features. Memory integrity is one feature in that area and is also called HVCI.
Does turning off Memory integrity require a restart?
Yes. Restart Windows for the change to take effect.
Why can’t I turn Memory integrity on?
An incompatible driver may be blocking it, or hardware virtualization may not be enabled in UEFI or BIOS. Check for a compatible driver update through Windows Update or the device manufacturer, and consult your PC manufacturer’s instructions for firmware settings.
Does Memory integrity require Secure Boot?
Microsoft’s guidance identifies hardware virtualization in UEFI or BIOS as a requirement. Secure Boot is a separate startup-security feature, not the same setting as Memory integrity.
Will turning off Memory integrity make a blocked driver work?
It may allow the driver to load, but the device or application may still fail. Disabling Memory integrity also reduces protection, so look for a compatible driver first.
What happens if I turn it off on a Secured-core PC?
The PC leaves its Secured-core state. Microsoft also warns that device functionality supported by the affected driver may not work as expected.
Can I enable Memory integrity with a command?
Use the Memory integrity switch in Windows Security under Device security > Core isolation details. The reviewed Microsoft guidance does not recommend Registry, PowerShell, or boot-configuration commands as a routine workaround.
The Bottom Line
In Windows 11, open Windows Security > Device security > Core isolation > Core isolation details and switch Memory integrity on or off. Keep it enabled when possible. If an incompatible driver prevents you from enabling it, seek a compatible update or remove the dependent device or app; turning protection off requires a restart and may not restore functionality.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

