Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Enabling Virtualization-based security (VBS) makes the Windows hypervisor create an isolated environment that Windows security features can run in. On its own, VBS is a platform, and the change you notice depends on which features use it. The best known of these is Memory integrity, which moves kernel-mode code integrity checks into that isolated environment and restricts certain kernel memory allocations. Other services, such as Credential Guard, rely on the same platform but have their own settings, default behavior, and compatibility limits. How much protection you actually get, and what it costs in speed, depends on your processor, your drivers and apps, and whether each service is running, not just on whether a toggle is switched on.

What enabling VBS actually changes

VBS uses the Windows hypervisor to create a virtual environment that is separate from the operating system kernel. Microsoft describes this environment as a root of trust that assumes the kernel itself could be compromised, so the security checks that run there do not depend on the kernel being clean. Turning VBS on does not, by itself, change what you see in everyday use. What changes is which protected services can start on top of it.

The three terms people mix up are easier to keep apart in a table:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Component What it is What it protects Default status
Virtualization-based security (VBS) The platform: the Windows hypervisor creates the isolated environment Provides the isolated environment that other features use Not turned on for every device; enabling it does not prove any feature above it is running
Memory integrity (also called HVCI or hypervisor-enforced code integrity) A VBS feature, documented by Microsoft as “a Virtualization-based security (VBS) feature available in Windows” Runs kernel-mode code integrity inside the isolated environment; protects the Control Flow Guard bitmap for kernel-mode drivers and the kernel-mode code integrity process; restricts kernel memory allocations that could be used to compromise the system Set by you or by policy; Windows 11 22H2 and later show a warning in Windows Security when it is off, which you can dismiss
Credential Guard A VBS-dependent service with separate configuration Isolates secrets such as NTLM password hashes and Kerberos Ticket Granting Tickets, so malware running with operating-system administrator privileges cannot extract them from that environment Conditional, described below

Treat these as separate settings. A PC can have VBS enabled with Memory integrity off, or with Memory integrity on and Credential Guard off.

Credential Guard: when it is on by default

Credential Guard is not automatically active on every Windows 11 computer. Microsoft says that starting with Windows 11, version 22H2, qualifying devices can have Credential Guard enabled by default if they meet the licensing, hardware, and software requirements and have not been explicitly configured to disable it. Microsoft’s overview of the feature describes this default-enablement context for domain-joined systems that are not domain controllers. If you explicitly disabled Credential Guard before upgrading, that choice carries over the upgrade.

Turning on Memory integrity on a single PC

On a personal or unmanaged PC, the switch is in Windows Security. Use the following path:

  1. Open Windows Security from the Start menu.
  2. Select Device security.
  3. Under Core isolation, select Core isolation details.
  4. Turn on the Memory integrity switch.

If Memory integrity is off on Windows 11 22H2 or later, Windows Security shows a warning. You can dismiss it, so the warning alone does not mean the protection is active.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Managed deployment and the UEFI lock choice

Administrators can deploy Memory integrity through Microsoft Intune or another configuration service that uses the Configuration Service Provider (CSP) policy, through Group Policy, through registry settings, or through App Control for Business. Microsoft’s policy CSP reference was last updated 2025-03-12, and its Memory integrity page was last updated 2026-08-14, so check both before writing deployment scripts.

When you configure the policy, you can enable Memory integrity with or without a UEFI lock. The two choices differ in what happens afterward:

  • Without UEFI lock: the setting can be changed by a later policy or by a remote change, and recovery is simpler.
  • With UEFI lock: the setting is intended to resist remote or policy-based disablement. Recovery is harder: Microsoft says that after enabling Memory integrity with UEFI lock, you must access UEFI settings to turn off Secure Boot as part of the documented recovery steps.

Choose the lock only when you have a tested recovery path for every device it will be applied to.

Rank #3

What you may notice: compatibility problems

Memory integrity can break drivers and applications that do not work with kernel code integrity checks running in the isolated environment. The usual symptom is that a program or device malfunctions. In rare cases, a device can fail to boot with a blue screen. Microsoft’s named examples include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Anti-cheat software used with some games.
  • Third-party input methods.
  • Third-party banking password protection tools.

For an affected app or driver, Microsoft recommends first checking for an update to that specific software or driver. For managed deployments, it recommends testing on a pilot group of computers before broad rollout.

Credential Guard compatibility

Credential Guard has its own application limits because it blocks some authentication capabilities. Microsoft lists Kerberos DES, unconstrained delegation, TGT extraction, and NTLMv1 as requirements that can break an application. Digest authentication, credential delegation, MS-CHAPv2, and CredSSP can expose credentials to risk when an application needs them. Microsoft recommends testing applications before deployment. It does not recommend enabling Credential Guard on domain controllers, and it states that the feature is unsupported on Exchange Server.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

Performance: depends on your processor

Microsoft’s guidance ties Memory integrity’s performance cost to processor features:

Processor support How Memory integrity runs Expected performance impact
Intel Kaby Lake and later, with Mode-Based Execution Control (MBEC) Uses the processor feature Microsoft says it works better on these processors
AMD Zen 2 and later, with Guest Mode Execute Trap (GMET) Uses the processor feature Microsoft says it works better on these processors
Older processors without these controls Relies on an emulation called Restricted User Mode Microsoft says the impact is bigger

The Microsoft pages reviewed for this article do not give a general percentage, a workload benchmark, or a promise of zero impact. Treat the processor generation as the main predictor, and test a representative workload on your own hardware before applying the setting to a fleet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security benefit and its limits

Memory integrity hardens kernel code integrity, and Credential Guard protects stored credentials from extraction by malware running with administrator privileges on the operating system. These are specific protections. They do not mean VBS blocks every attack. Microsoft cautions that persistent attackers may shift to other techniques, and it recommends a broader security strategy alongside these features.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

How to confirm what is actually running

A policy or toggle can be set while the feature is still not running. To check the device state, open PowerShell as administrator and run:

Get-CimInstance -ClassName Win32_DeviceGuard -Namespace rootMicrosoftWindowsDeviceGuard

The output includes these fields:

Field Values or meaning
VirtualizationBasedSecurityStatus 0 means VBS is not enabled; 1 means enabled but not running; 2 means enabled and running
SecurityServicesConfigured Lists which security services are configured, such as Credential Guard or Memory integrity
SecurityServicesRunning Lists which of those services are actually running

For a quicker visual check, run msinfo32.exe. Its System Summary page displays the VBS features. If the configured list includes a service that is missing from the running list, the setting has been applied but has not taken effect yet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recovering if the device becomes unstable

If a device becomes unstable, or shows a critical boot error after Memory integrity is enabled, Microsoft documents recovery through the Windows Recovery Environment. The documented steps include disabling the policy that enabled VBS or Memory integrity, setting the Memory integrity registry value to off, and restarting. If UEFI lock was used, Secure Boot must be turned off in UEFI settings to complete these steps. Keep that UEFI access in mind before enabling the lock on a machine you cannot easily reach.

Sources and dates

This article is based on Microsoft Learn documentation accessed 2026-10-07, including the Memory integrity guidance (last updated 2026-08-14), the policy CSP reference (last updated 2025-03-12), and the Credential Guard overview. Microsoft’s pages can change, particularly default-enablement rules and driver compatibility lists, so check the current versions before making deployment decisions. No adoption rate or protection statistic for VBS was identified in these documents, and this article does not offer one.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$285.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$245.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.