Expanding memory integrity protection across Windows devices

🚨 The Signal: Windows quality updates will automatically enable Memory Integrity and Virtualization-Based Security (VBS) on more eligible devices starting October 2026. This enhances kernel protection against tampering, improving device security posture.

The Impact

All Windows devices will benefit from enhanced kernel protection, reducing the risk of advanced malware and rootkits.

  • Security Teams: Reduced risk from kernel-level attacks.
  • Admins: Review existing policies to ensure desired state.
  • All Windows Devices: Enhanced built-in security features.
  • Organisations: Improved compliance posture for endpoint hardening.

The Action

  1. Review existing Memory Integrity and VBS policies in Intune or Group Policy.
  2. Consult Microsoft documentation on 'Expanding memory integrity protection across Windows devices' for rollout details.
  3. Refer to 'Enable memory integrity' for detailed configuration and management guidance.
  4. Assess device readiness and compatibility for Memory Integrity and VBS enablement.

Domain: Intune · Impact: medium · Workload: Other · Essential Eight: Patch Operating Systems, User Application Hardening · ISM: ISM-1407, ISM-1412, ISM-1485, ISM-1486, ISM-1501, ISM-1542, ISM-1585, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1694, ISM-1695, ISM-1696, ISM-1701, ISM-1702, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1877, ISM-1889, ISM-1902