Microsoft is working on expanding its memory integrity protection feature across its global Windows 11 installations, with the rollout beginning in October. For those unaware, memory integrity protection enhances operating system security at the kernel level, safeguarding it from sophisticated attacks by malicious actors.
This feature is straightforward, requiring little to no additional configuration from the user, meaning any complexity is hidden while the PC remains significantly more secure. Using Virtualization-based Security (VBS), the OS employs hardware virtualization to create Windows hypervisors that dedicate isolated virtual environments.
The OS operates under the assumption that the kernel can be compromised. Microsoft developed this robust protection mechanism using Virtualization-based Security (VBS), allowing for more security hotpatches to be installed on the fly without needing a hard restart.
For installations running in critical environments, this means the OS will continue running its dedicated tasks while receiving constant security updates. For large organizations with managed Windows 11 devices, setup will be easy as all devices will automatically benefit from the memory integrity addition.
All existing admin and user decisions and policies will remain fully in effect, while devices with memory integrity currently disabled will not have it automatically enabled by the October rollout. Read full story