Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Windows » Enable or disable Core Isolation Memory Integrity in Windows 10 and 11
  • Jenkins
    How to Install Jenkins Automation Server on Ubuntu 20.04 LTS Linux
  • Install RSAT on Windows 11 today
    Install Remote Server Administration Tools on Windows 11 Windows
  • MachineAccountQuota
    Change the number of MachineAccountQuota a user can add to AD Windows Server
  • http to https redirection
    URL Rewrite: How to redirect from HTTP to HTTPS Web Server
  • How to Enable or Disable Inherited Permissions for Files and Folders in Windows
    How to Enable or Disable Inherited Permissions for Files and Folders in Windows Windows
  • VMware Tech Showcase
    Great details on VMware Tech Showcase Virtualization
  • Featured image 5
    How to uninstall and prevent the installation of Microsoft Teams on Windows Windows
  • images 5 3
    How to uninstall AWS CLI in Windows AWS/Azure/OpenShift

Enable or disable Core Isolation Memory Integrity in Windows 10 and 11

Posted on 15/12/202201/10/2023 Christian By Christian No Comments on Enable or disable Core Isolation Memory Integrity in Windows 10 and 11
CoreIsolationprotection

Core isolation is a security feature of Microsoft Windows that protects important core processes of Windows from malicious software by isolating them in memory. It does this by running those core processes in a virtualized environment. Memory integrity is also referred to as Hypervisor-protected Code Integrity (HVCI) which is a Windows security feature that makes it difficult for malicious programs to use low-level drivers to take over your device. It is designed to prevent attacks from inserting malicious code into high-security processes. Memory integrity works by creating an isolated environment using hardware virtualization.

A driver is a piece of software that lets the operating system (Windows in this case) and a device (like a keyboard or a webcam, for two examples) talk to each other. When the device wants Windows to do something, it sends that request to the driver.

Here are some related guides: Upgrade Driver Automation Tool: How to automate Windows drivers with the SCConfigMgr on Windows, how to delete obsolete drivers from the Driver Store in Windows 10,  how to import drivers in .exe format into Microsoft Deployment Toolkit, how to determine the version and type of a Printer Driver, and how to add Print Drivers with PowerShell, RUNDLL32, and VBScript in Windows 10.

Core Isolation Memory Integrity requirements

There are some requirements for this security feature. The hardware must also support it; it cannot only operate at the software level. Your firmware needs to handle virtualization, enabling the Windows 11/10 PC to execute apps in a container without granting them access to other system components. Also, your device must comply with the standards for hardware security, including:

  • UEFI MAT (Unified Extensible Firmware Interface Memory Memory Attributes Table)
  • Secure Boot needs to be enabled.
  • DEP (Data Execution Prevention)
  • TPM 2.0 needs to be enabled. 
  • CPU Virtualization needs to be enabled. 
  • UEFI MAT and DEP should be supported if you have a reasonably new system configuration (less than 7 years old). 

Enable and disable the Core Isolation Memory Integrity in Windows Security

In this guide, I will be showing you how to turn on or off core isolation memory integrity in Windows 11. We will be enabling and disabling the Core Isolation Memory Integrity in Windows Security.

To do this, open Windows Security, and click on Device Security as shown below.

image-7

Click on the Core isolation details link. Now you can enable or disable Memory Integrity as shown below by toggling the switch to on or off.

As you can see, it is currently disabled. Please toggle the button to enable it.
image-8

Here are some exciting articles: Hyper-V Server Core Mode: How to install free Hyper-V Server on a VMware Workstation. How to fix “The module ping was not found in configured module paths, core modules are missing“, and How to check Hard Drive Health (SMART) in Windows.

Once you’ve completed the steps, you will need to restart your computer to apply the new change.

If memory integrity fails to turn on it may tell you that you have an incompatible device driver already installed. Check with the manufacturer of the device to see if they have an updated driver available.

If they don’t have a compatible driver available, you might be able to remove the device or app that uses that incompatible driver. Otherwise, you can uninstall any incompatible drivers.

Enable or Disable Core Isolation Memory Integrity via the Windows registry

You can also enable or disable Core Isolation Memory Integrity using Windows registry keys. Here are some guides relating to Windows Registry: How to add Registry keys via DISM in Windows, how to Get, Edit, Create and Delete Registry Keys via PowerShell in Windows, and how to disable IE via Group Policy or Windows Registry Settings

  1. Use the Windows key + R keyboard shortcut to open the Run command.
  2. Type regedit, and click OK to open the Registry.
  3. Browse the following path:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity
  4. Double-click the Enabled key.
  5. Set it value from 0 to 1.
  6. Click OK.

If you wish to disable Core memory integrity via the Windows registry, follow the same steps as above, this time. Set the value from 1 to 0. After completing the steps, restart your computer to apply the changes.

Upon Upgrading from Windows 10 to Windows 11. “Core Isolation” – Memory Integrity security features use virtualization-based security to protect your core operating system processes from tampering, but “Memory Protection” is off by default for users that upgrade from w10 to 11.

Why is Memory Integrity disabled by Default in Windows 11 upon Upgrade?

Note: If your device does not have compatibility issues, Memory Integrity will be enabled by default.

The main Core Isolation feature is an issue per se. Because it is disabled upon upgrade. It’s enabled on all Windows 10 PCs that can support it because there is no interface for disabling it.

However, Memory Integrity protection can cause issues with some device drivers or low-level Windows applications, which is why it’s disabled by default on upgrades. Microsoft is still pushing developers and device manufacturers to make their drivers and software compatible, which is why it’s enabled by default on new PCs and new installations of Windows 10, and 11.

Please see How to secure the Windows 10 boot process, how to run Windows Memory Diagnostics Tool on Windows, and New Windows 11 Encryption: Enhancing Security for Hybrid Work.

If one of the drivers your device requires to boot is incompatible with Memory Protection. Windows will silently turn Memory Protection off to ensure your PC can boot and work properly. So, if you try enabling it and rebooting only to find it’s still disabled, that’s why. 

If you encounter problems with other devices or malfunctioning software after enabling Memory Protection. Microsoft recommends checking for updates with the specific application or driver. If no updates are available, turn off Memory Protection.

I hope you found this blog post helpful on “how to enable or disable Core Isolation Memory Integrity”. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Microsoft Windows, Windows 10, Windows 11, Windows Security

Post navigation

Previous Post: How to retrieve deleted WhatsApp messages on iPhone
Next Post: How to enable Smart App Control on Windows 11

Related Posts

  • schedulepythontasksinWindows
    Run Python Script via Windows Task Scheduler Windows
  • Featured image samp
    How to use Windows 11 PC Health Check App Windows
  • Remote Desktop Connection Windows 10 min
    Fix Remote Desktop Connection issues (Error 0x204) Windows
  • Azure Backup 1
    How to Install Azure Backup Agent AWS/Azure/OpenShift
  • Laptop battery performance report
    Windows Battery Report: Track down a malfunctioning laptop battery Windows
  • screenshot 2020 03 07 at 22.25.21
    How to export and import User Profile – FrontFace Lockdown Tool Windows

More Related Articles

schedulepythontasksinWindows Run Python Script via Windows Task Scheduler Windows
Featured image samp How to use Windows 11 PC Health Check App Windows
Remote Desktop Connection Windows 10 min Fix Remote Desktop Connection issues (Error 0x204) Windows
Azure Backup 1 How to Install Azure Backup Agent AWS/Azure/OpenShift
Laptop battery performance report Windows Battery Report: Track down a malfunctioning laptop battery Windows
screenshot 2020 03 07 at 22.25.21 How to export and import User Profile – FrontFace Lockdown Tool Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Jenkins
    How to Install Jenkins Automation Server on Ubuntu 20.04 LTS Linux
  • Install RSAT on Windows 11 today
    Install Remote Server Administration Tools on Windows 11 Windows
  • MachineAccountQuota
    Change the number of MachineAccountQuota a user can add to AD Windows Server
  • http to https redirection
    URL Rewrite: How to redirect from HTTP to HTTPS Web Server
  • How to Enable or Disable Inherited Permissions for Files and Folders in Windows
    How to Enable or Disable Inherited Permissions for Files and Folders in Windows Windows
  • VMware Tech Showcase
    Great details on VMware Tech Showcase Virtualization
  • Featured image 5
    How to uninstall and prevent the installation of Microsoft Teams on Windows Windows
  • images 5 3
    How to uninstall AWS CLI in Windows AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,836 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.