What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you’re looking for a useful Windows security setting to check, start with Memory integrity in Windows Security. It helps protect Windows’ kernel from malicious or untrusted code, but it requires hardware virtualization and can be blocked by incompatible drivers. The title could also refer to other built-in protections; Microsoft’s Device security page is the place to check what your PC supports and whether those protections are enabled.

Where to find Windows’ built-in security controls

Open Windows Security from the Start menu and select Device security. The page summarizes hardware and firmware protections available on the PC, including Core isolation, the security processor (TPM), and Secure Boot. The available options vary by Windows version and installed hardware; Windows 10 and Windows 11 are both covered by Microsoft’s Device Security support guidance, but labels and availability can differ.

Microsoft’s Device Security in the Windows Security App explains that the page’s hardware security capability assessment includes TPM 2.0, Secure Boot, DEP, UEFI MAT, Core isolation support, and Memory integrity. If Windows says a capability is “not supported,” at least one stated requirement is unmet. That message alone does not mean the entire PC is insecure.

How to check and enable Memory integrity

Memory integrity, also known as Hypervisor-protected Code Integrity (HVCI), uses hardware virtualization to isolate checks on kernel code. Microsoft says this makes it more difficult for malicious programs to use low-level drivers to hijack a PC. It is a targeted protection, not a guarantee against malware or other attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Open Windows Security and select Device security.
  2. Select Core isolation details.
  3. Check the status of Memory integrity. If the option is available and off, use its toggle to turn it on.
  4. Follow any prompt to restart Windows, then return to the same page to check the status.

Memory integrity requires hardware virtualization to be enabled in UEFI/BIOS. If Windows reports an incompatible driver, first look for an updated driver from the device’s manufacturer. Removing the affected device or app may be an option only if no compatible driver is available and you no longer need it; don’t remove a driver just because the setting is blocked.

Check TPM and Secure Boot before changing firmware settings

On Device security, open the security processor details to inspect the TPM, and check the Secure Boot status shown on the page. If there is no Security processor entry, Microsoft says the PC may lack TPM hardware or TPM may be disabled in UEFI. Check the PC manufacturer’s support information before changing firmware settings: a separate TPM module is not a general fix, since a TPM may already be present, firmware-based, or simply disabled, and add-on compatibility depends on the motherboard.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Secure Boot checks the software involved in starting the PC. Microsoft says most modern PCs support it, though firmware settings can make it appear unavailable. To reach the firmware interface from Windows, go to Settings > System > Recovery > Advanced startup, select Restart now, then choose Troubleshoot > Advanced options > UEFI Firmware Settings. The exact screens and options vary by manufacturer. Moving from Legacy/CSM boot to UEFI may be involved, so use the PC maker’s instructions if you are unsure rather than changing boot settings by trial and error.

Secure Boot can conflict with some hardware or operating-system configurations, including some graphics cards, Linux setups, or older Windows versions. Microsoft says it may sometimes need to be temporarily disabled to resolve an issue and recommends turning it back on afterward. Don’t change it without a specific reason and a recovery path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What each setting does—and what it asks of your PC

Setting Protection focus Requirements or friction Where to check
Memory integrity Helps protect kernel code from malicious or untrusted drivers. Requires hardware virtualization in UEFI/BIOS; incompatible drivers can block it. Windows Security > Device security > Core isolation details.
TPM / security processor Hardware-based security capability used by Windows; the Device security page reports its status and details. Depends on TPM hardware or firmware support and whether it is enabled in UEFI. Windows Security > Device security > Security processor details, when shown.
Secure Boot Helps protect the startup chain by checking software involved in booting. Depends on UEFI firmware support and configuration; some hardware or operating-system setups may have compatibility issues. Windows Security > Device security; firmware settings are reached through Advanced startup.
Smart App Control Helps block untrusted or potentially harmful apps. Has separate eligibility and Windows installation/evaluation conditions; it is not simply another Device security toggle. Windows Security > App & browser control.

Microsoft’s App & browser control in the Windows Security App describes Smart App Control’s modes and evaluation conditions. Check that guidance and the status shown on your PC before treating it as an option you can freely switch on.

Two cautions before you troubleshoot

  • Don’t clear the TPM casually. Clearing it is a troubleshooting or recovery action, not a routine way to enable protection. Microsoft advises backing up data before clearing the TPM.
  • Don’t assume one enabled setting makes a PC secure. These controls address specific parts of device security, and Microsoft’s support material does not quantify how much enabling one reduces an ordinary user’s overall risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A time-sensitive Secure Boot detail

Microsoft’s Windows 11 and Secure Boot guidance says Secure Boot certificates issued in 2011 start expiring in June 2026. The page says a PC running a supported Windows version will receive the certificate update automatically. That statement concerns this certificate update specifically; it is not a promise that every firmware or Secure Boot problem will resolve automatically.

Best Value
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.