REDMOND, Washington — Microsoft on Friday began rolling out a Windows 11 update that enables memory integrity protection by default on eligible PCs. The change targets kernel-level attacks that exploit vulnerable drivers.

Memory integrity, also called Hypervisor-Protected Code Integrity, uses virtualization-based security to isolate critical kernel processes. Microsoft said the feature would activate automatically only on devices meeting driver-compatibility requirements, with unsupported systems left unchanged. The rollout follows months of testing through the Windows Insider Program.

The Microsoft Security Response Center said the move addresses a persistent class of "bring your own vulnerable driver" attacks, in which criminals load legitimately signed but flawed drivers to bypass protections. Security researchers at firms including CrowdStrike have documented a sharp rise in such techniques over the past year.

Microsoft acknowledged that some older peripherals, anti-cheat systems and virtualization tools may experience conflicts. The company advised users encountering performance or compatibility issues to update drivers or temporarily disable the feature through the Windows Security app. Enterprise administrators can manage the setting through group policy.

The decision extends a broader Microsoft strategy of making hardware-backed security defaults rather than opt-in features, following earlier requirements for TPM 2.0 and Secure Boot. Analysts at Forrester have said such mandates accelerate the retirement of aging enterprise hardware, a cost many IT departments have resisted.