Quick answer

Leave it on. On an Intel 7th-gen (Kaby Lake) or AMD Zen 2 or newer CPU, reviewer tests put the cost at about 2 to 6 percent of average frame rate in CPU-limited games and about 2 percent at 4K. Riot Vanguard or FACEIT may require it. Test it off only on an older CPU.

Leave it on. On a CPU from the last several generations the published tests put the cost in single digits, the bigger losses showing up in games where the processor is the limit, and from October 2026 Microsoft begins turning it on through Windows updates for eligible PCs that never had it. Two things can take the choice away from you. Riot Vanguard and FACEIT can refuse to start a match until it is running. And a CPU old enough to lack the hardware support Microsoft names pays more, which is the one case where I would test it off.

Memory Integrity on or off: the decision

Find your row first. The last column is what I would set.

Your situationWhat the sources saySet it
A Riot game shows VAN: RESTRICTION: 5Vanguard could not verify that Memory Integrity is enabled and runningOn, or the game will not let you play
FACEIT’s anti-cheat asks for itFACEIT says you need it only when its anti-cheat specifically requires itOn
Intel Kaby Lake (7th-gen) or newer, AMD Zen 2 or newerMicrosoft says memory integrity works better with Intel’s Mode-Based Execution Control and AMD’s Guest Mode Execute Trap; tests on these chips found about 2 to 6 percent at 1080pOn
An older CPU without those featuresWindows falls back to an emulation called Restricted User Mode, which Microsoft says will have a bigger impact on performance; I found no published game test on such a CPUTest it off in your own game, and turn it back on if the gain is within noise
A CPU-limited esports game at very high frame ratesXDA’s CS2 run on a Ryzen 5 7600X lost 1.7 percent of average FPS, while its 1% lows were higher with it onOn, unless your own runs show a loss
An incompatible driver blocks it and no game requires itMicrosoft’s advice is an updated driver from the maker, or removing the device or app that uses itFix the driver; leave it off only if you need that hardware and no update exists

If you are not sure which CPU class you have, Windows will tell you. The check is further down.

What it costs in games: the tests that exist

I have not benchmarked memory integrity, so this section is other people’s measurements, with the hardware and date of each. Every one of them ran on a CPU that has the hardware support Microsoft names.

TestHardwareWhat it found with the feature on
Tom’s Hardware, October 9, 2021Core i7-11700K, Core i7-10700K, Ryzen 7 5800X, Ryzen 7 3800X; RTX 3090; 1080pVBS plus memory integrity cost 5.6, 5.7, 3.3 and 4.1 percent of average FPS (geometric mean). VBS alone cost 4 to 5 percent, so the memory integrity layer added little on these chips. Worst single result with VBS on was Red Dead Redemption 2 under DX12 on the 3800X, 8.6 percent slower
Tom’s Hardware, March 14, 2023Core i9-13900K, 32 GB DDR5-6600, RTX 4090Turning VBS off improved performance by up to 5 percent across the test suite and about 2 percent at 4K ultra. Microsoft Flight Simulator gained around 10 percent, with 1% lows up to 15 percent higher
XDA, September 14, 2026Ryzen 5 7600X, RTX 4070 Ti Super; 1080p, low presetCS2 averaged 398.2 FPS on and 404.8 off (1.7 percent). Cyberpunk 2077 averaged 183.1 on and 186.5 off (1.9 percent), with 1% lows 6.6 percent better off. In CS2 the 1% lows were 5.2 percent better with it on

Three patterns hold across all three. The loss is largest where the CPU is the bottleneck: 1080p, low settings, simulators. It shrinks as the GPU takes over, which is why the 4K ultra figure is about 2 percent. And the 1% lows move both ways from game to game, better with it on in XDA’s CS2 run and worse in its Cyberpunk run, so another PC’s averages cannot settle it for yours.

What none of them covers is a CPU that predates Kaby Lake or Zen 2. Microsoft’s own documentation is the only source on that class, and it says the impact is bigger without giving a number. If you are on one of those chips, the only figure that matters is your own: test it the way the HAGS page describes, three logged runs each way in the same scene, comparing 1% lows as well as averages.

Tom’s 2021 article also quoted Microsoft’s guidance to PC makers that some devices “especially sensitive to performance (e.g. gaming PCs)” may choose to ship with it disabled, with a recommendation to test thoroughly first. Microsoft later published a consumer page, Options to optimize gaming performance in Windows 11, that let gamers turn memory integrity and the Virtual Machine Platform off while gaming and on again afterwards, warning that the device “may be vulnerable to threats” while they are off. That page is retired. Its address now redirects to the Microsoft Support home page, and the last archived copy is from October 17, 2025. I would not treat it as Microsoft’s current advice.

When anti-cheat decides for you

Riot Vanguard (Valorant, League of Legends). Riot’s security requirements page says Vanguard “may require certain Windows security features” and that, depending on your system configuration, it may prompt you to enable one or more. It lists four: TPM 2.0, Secure Boot, Memory Integrity (HVCI/VBS) and IOMMU. The one that names this setting is VAN: RESTRICTION: 5. Riot says it appears when Memory Integrity is off, when virtualization is not fully enabled, or when a required BIOS/UEFI security setting is not configured correctly. The fix is the one below, then a restart. Other VAN codes are on the Vanguard error codes page, and the Secure Boot and TPM ones on the Secure Boot fix.

FACEIT. FACEIT’s Memory Integrity article opens by saying you do not need to enable it unless FACEIT Anti-Cheat specifically requires you to. The reason it can, from FACEIT’s security FAQ, is IOMMU, its defense against DMA-card cheats: “We require VBS to support IOMMU reliably on Windows.” The same FAQ says IOMMU is being enforced in waves, and concedes that IOMMU and VBS “can have a minor performance impact in some cases, particularly on older systems.”

So the requirement is conditional at both companies. If neither has asked you, nothing forces your hand. Easy Anti-Cheat’s support page says games using it “may impose additional security requirements on players which are controlled by the developer”, and the requirements it describes there are Secure Boot and TPM, plus IOMMU. Memory integrity is not among them. Its own fixes are on the EAC repair guide.

What changes in October 2026

Microsoft’s September 1 announcement says that “Beginning in October 2026” Windows quality updates will begin enabling memory integrity on eligible devices, and VBS too where it is not already on. Before it flips the switch, Windows evaluates readiness signals that Microsoft lists as hardware capabilities, compatibility and performance considerations. The post gives no day and no update number, so any date you read elsewhere is someone’s inference.

The exemption is one sentence: devices “where memory integrity has already been disabled won’t be automatically changed by this rollout.” Microsoft does not say whether a PC upgraded from Windows 10, where nobody ever touched the switch, counts as disabled. Its hardware documentation still says auto-enablement applies only to clean installs, not upgrades, which the September post plainly goes beyond. I would not assume either way. Check the state after each monthly update from October on.

The clean-install floor in that same document gives an idea of what “eligible” has meant so far:

  • Intel 8th generation or later from Windows 11 version 22H2, AMD Zen 2 and newer, Qualcomm Snapdragon 8180 and newer (Intel 11th-gen desktop chips are not in the default logic, Microsoft notes)
  • 8 GB of RAM (on x64 processors), and an SSD of at least 64 GB
  • memory-integrity-compatible drivers, and virtualization enabled in the BIOS

That this switch would come through Windows Update is new. In 2023, Tom’s Hardware corrected its own article to say Windows updates did not enable VBS. Microsoft’s September post says that changes from October 2026.

Check whether it is on

Two ways, both from Microsoft and Riot.

  1. Press Windows + R, type msinfo32 and press Enter. At the bottom of System Summary, Virtualization-based security should read Running, and Virtualization-based security Services Running should include Hypervisor enforced Code Integrity. Riot’s enable guide uses exactly this check.
  2. For the CPU question, open PowerShell as administrator and run:
Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard

Microsoft’s documentation decodes the output. A 7 in AvailableSecurityProperties means MBEC/GMET is available, so you are in the cheaper class. A 2 in SecurityServicesRunning means memory integrity is running, and VirtualizationBasedSecurityStatus reads 2 when VBS is enabled and running.

Windows Security also warns you. Since Windows 11 22H2 it shows a warning, on its taskbar icon too, when memory integrity is off, and you can dismiss it from inside the app. A “memory integrity is off” notice is that warning; it does not mean something broke.

How to turn it off, and back on

Open Windows Security > Device security > Core isolation details and switch Memory integrity off or on. It needs administrator rights and a restart. That is the whole procedure on a home PC, and the same switch brings it back.

My default is to leave it on. If you turn it off to test, write down what you saw and turn it back on unless the gain in your own game is clearly larger than run-to-run noise. Microsoft’s retired gaming page gave the same instruction, to turn it back on when finished playing, because while it is off “the device may be vulnerable to threats.”

Two warnings before anyone uses Group Policy. In Computer Configuration > Administrative Templates > System > Device Guard > Turn on Virtualization Based Security, Microsoft says to pick Enabled without UEFI lock. With Enabled with UEFI lock, turning memory integrity off later requires going into the UEFI menu and turning Secure Boot off, which is a change with its own risks; the Secure Boot fix covers that order. And the registry’s Mandatory value makes Windows refuse to boot if the virtualization modules fail to load. Neither belongs on a gaming PC.

Memory Integrity can’t be turned on

Incompatible drivers

This is the common one. Microsoft’s Windows Security help says that if memory integrity fails to turn on, it may tell you an incompatible driver is installed, and that the fix is an updated driver from the maker or removing the device or app that uses it.

  1. On the Core isolation page, select Review incompatible drivers and note each driver’s name and publisher.
  2. Check the maker’s site for a current version. FACEIT says these are often left over from old mouse, keyboard or RGB software, and Riot adds older anti-cheat and hardware drivers to that list.
  3. If it belongs to software you no longer use, uninstall that software through Settings rather than deleting driver files by hand.
  4. Restart and try the switch again.

To see every third-party driver at once, Riot suggests dism /online /get-drivers /format:table in an administrator Command Prompt. Microsoft’s hardware documentation adds where blocked drivers are logged: Event Viewer, Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational, event ID 3087.

The switch is missing, or VBS shows “Enabled but not running”

Memory integrity needs hardware virtualization turned on in the BIOS. On Intel boards Riot names the setting Intel Virtualization Technology (VT-x), on AMD boards SVM Mode. Task Manager’s Performance > CPU page shows Virtualization: Enabled once it is on. If the Core isolation page itself says “Page not available”, Riot’s first suggestion is to update Windows. Changing BIOS settings carries its own risk, and Riot’s guide says plainly that a wrong setting can stop the PC from starting, so change only the virtualization option and leave Secure Boot to its own guide.

“This setting is managed by your administrator”

Something other than the switch is in charge. Microsoft documents that Group Policy, Intune and App Control for Business can each turn memory integrity on (App Control does so even in audit mode), and that deleting the WasEnabledBy registry value grays the switch out with exactly this message. On a work or school PC, stop there and ask the administrator.

On your own PC, Microsoft’s documented command to make the switch behave normally again is below. Registry edits can stop Windows from starting if you get them wrong, so create a restore point first and type the line exactly as shown.

reg add HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity /v "WasEnabledBy" /t REG_DWORD /d 2 /f

It turns off after a restart, or a blue screen follows

Windows can have a safeguard for exactly this. Microsoft’s hardware documentation describes two registry values, recommended for PC makers’ Windows images, that make a device “automatically turn off memory integrity if the system crashes during boot, potentially caused by memory integrity blocking an incompatible boot-critical driver”, for up to three boots after it was enabled. If yours keeps switching itself off, a driver is failing. Find it in the CodeIntegrity log above and update or remove it before turning the switch back on.

If it turns back on after you switched it off, look for a policy: Group Policy, an Intune profile or an App Control policy, the same causes as the “managed by your administrator” message above.

If the PC will not boot at all after enabling it, Microsoft’s recovery steps run in this order. Before the first one, have your BitLocker recovery key ready: Microsoft’s BitLocker documentation says that when Windows RE is started by hand from a repair disk, the recovery key must be entered before the drive opens.

  1. Disable any policy that turns on VBS and memory integrity, such as Group Policy. Microsoft lists this as the first step.

  2. Boot the PC into the Windows Recovery Environment and open Command Prompt (Riot’s guide gives the path as Troubleshoot > Advanced options > Command Prompt).

  3. Set memory integrity off with Microsoft’s command:

    reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /v "Enabled" /t REG_DWORD /d 0 /f
    
  4. Restart.

If memory integrity was turned on with the UEFI lock, Microsoft notes that you also have to turn Secure Boot off to complete these steps; that is a firmware change with its own order, covered on the Secure Boot fix. Microsoft’s page, and Riot’s guide that gives the same command, do not explain how a command typed in the recovery environment reaches the installed copy of Windows rather than the recovery environment’s own registry. If the PC still will not start after these steps, stop editing the registry and take it to Microsoft support or a technician.

Once Windows is back, fix the driver, then switch memory integrity on again from Windows Security.

What Memory Integrity does

Memory integrity, also called hypervisor-protected code integrity (HVCI), moves the check that decides whether kernel-mode code and drivers are trusted into an isolated environment that the Windows hypervisor builds, which Microsoft calls virtualization-based security. Malware that reaches the kernel then has a much harder time loading its own driver. Core isolation is just the Windows Security page where the switch lives. The tests above show the cost landing on the CPU side: it shrinks as a game becomes GPU-bound.

For the other Windows settings gamers get told to change, see Game Mode on or off and Resizable BAR on or off.

Sources

Frequently asked questions

Should Memory Integrity be on or off for gaming?
On, for most gaming PCs. On an Intel Kaby Lake (7th-gen) or AMD Zen 2 or newer CPU, which Microsoft says run it with hardware support, published tests found about 2 to 6 percent lower average frame rate in CPU-limited runs and about 2 percent at 4K ultra. Riot Vanguard and FACEIT can require it. An older CPU falls back to an emulation Microsoft says has a bigger performance impact, and that is the case worth testing with it off.
Does Memory Integrity lower FPS?
A little, and most in CPU-limited games. Tom’s Hardware measured 3.3 to 5.7 percent lower average frame rate at 1080p across four Intel and AMD CPUs with VBS and memory integrity on (October 2021). In March 2023 it found turning VBS off was worth up to 5 percent on a Core i9-13900K and RTX 4090, about 2 percent at 4K ultra, with Microsoft Flight Simulator near 10 percent. XDA measured 1.7 and 1.9 percent on a Ryzen 5 7600X in September 2026.
Will Windows turn Memory Integrity on by itself in October 2026?
On eligible PCs, yes. Microsoft says that beginning in October 2026 Windows quality updates will begin enabling memory integrity, and VBS if needed, on eligible devices after checking hardware, compatibility and performance. It names no date and no update number. Devices where memory integrity has already been disabled will not be changed, Microsoft says, but the post does not define what counts as disabled.
Do I need Memory Integrity for Valorant?
Only if Vanguard asks for it. Riot says Vanguard may require certain Windows security features depending on your system configuration, and Memory Integrity is one of four it lists. The error that names it is VAN: RESTRICTION: 5, which means Vanguard could not verify that Memory Integrity is enabled and running. Turn it on, restart, and check that msinfo32 shows Virtualization-based security as Running.
Does FACEIT require Memory Integrity?
Only when the FACEIT anti-cheat tells you to. FACEIT’s own article says you do not need to enable it unless FACEIT Anti-Cheat specifically requires you to in order to continue playing. Its security FAQ says FACEIT requires VBS to support IOMMU reliably, and that IOMMU is being enforced in waves rather than for every player at once.
Why can’t Memory Integrity be turned on?
Usually an incompatible driver. Open Windows Security > Device security > Core isolation details and select Review incompatible drivers, note the driver and its publisher, then update it from the maker or uninstall the software that installed it. FACEIT says these are often left over from old mouse, keyboard or RGB software. If the switch is missing or VBS shows Enabled but not running, hardware virtualization is probably off in the BIOS.
Why does Memory Integrity say ‘This setting is managed by your administrator’?
A policy or a registry value is controlling it. Microsoft documents that Group Policy, Intune and App Control for Business can all turn memory integrity on, and that deleting the WasEnabledBy registry value grays out the switch with that exact message. On a work or school PC, ask the administrator. On your own PC, Microsoft’s documented value WasEnabledBy = 2 returns the switch to normal.
Why did Memory Integrity turn itself off after a restart?
Windows may have switched it off to keep the PC bootable. Microsoft’s documentation describes a safeguard that turns memory integrity off automatically if the system crashes during boot, typically because it blocked an incompatible boot-critical driver. Look in Event Viewer under Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational for event ID 3087, fix that driver, then turn it back on.
Is Memory Integrity the same as Core isolation and VBS?
They are layers of one feature. Core isolation is the Windows Security page. Memory integrity is the switch on it, also called hypervisor-protected code integrity (HVCI). It runs inside virtualization-based security (VBS), which uses the Windows hypervisor to build an isolated environment. Riot’s and FACEIT’s error messages use all of these names for the same requirement.

Sources and corrections

Last updated
Methodology
See our methodology for research and review standards. It draws on 15 cited sources, listed below, each checked against the original page on the date above. No benchmark on this page is mine. The performance figures are Tom’s Hardware’s (October 2021 and March 2023) and XDA’s (September 2026), each named with its hardware and date. Microsoft’s October 2026 change is quoted from its own announcement, and the anti-cheat requirements from Riot’s, FACEIT’s and Easy Anti-Cheat’s support pages, all opened on 2026-10-02. Microsoft’s retired gaming-performance page is cited from its Wayback Machine capture of October 17, 2025, because the live address now redirects to the Microsoft Support home page.
Sources
Update log
  • 2026-10-02 — Page updated.
Corrections
Spotted an error or a stale number? Email contact@techfuelhq.com. Confirmed corrections are added to the update log above.

About the author

Written by Lowell K. Wood IV, who builds and runs TechFuelHQ from St. Louis, Missouri.