Skip to content
Follow
Windows

How to Enable Kernel-Mode Stack Protection in Windows 11

Richard
Written by
Richard
Mar 30, 2026 Updated Oct 4, 2026 5 min read
How to Enable Kernel-mode Stack Protection in Windows 11
How to Enable Kernel-mode Stack Protection in Windows 11

Kernel-mode Hardware-enforced Stack Protection is a built-in security setting in Windows 11. It stops malicious software from taking over your PC through memory tricks. It is available on Windows 11 version 22H2 and later. It watches how code runs in the kernel, the core of the operating system, and blocks attempts to redirect that code.

Advertisement

You turn it on in the Windows Security app. You can also set it through the registry, which is covered further down. Both Windows 11 Home and Pro include the setting. It is only usable on supported hardware.

⚡ Quick Answer

Open Windows Security, click Device security, then Core isolation details. Find Kernel-mode Hardware-enforced Stack Protection and toggle it on. Restart your computer to apply the change. The feature requires Windows 11 version 22H2, supported Intel or AMD hardware with virtualization enabled, and Memory Integrity turned on.

Advertisement

How It Works

Many attacks work by overwriting a return address. That is the spot in memory that tells a function where to go back to when it finishes. If an attacker changes it, the program jumps to the attacker’s code instead of its own.

Stack protection closes that gap. The processor (CPU) keeps a second, protected copy of each return address on a shadow stack. When a function returns, the CPU compares the two addresses. If they don’t match, the return is blocked. Software can’t write to the shadow stack the way it can to the normal stack, so the copy is hard to tamper with.

What You Need

  • CPU: Intel Tiger Lake (11th Gen) or newer with Control-Flow Enforcement Technology (CET), or AMD Zen 3 Ryzen or newer with AMD shadow stacks
  • CPU virtualization turned on
  • Memory Integrity turned on

The feature depends on both hardware and settings. If your processor is older than the ones listed, the option will not appear or will not work. You can’t fix that with a setting.

CPU virtualization is usually switched on in your UEFI/BIOS firmware settings. It often goes by a name like Intel Virtualization Technology (VT-x) or AMD-V/SVM. Many new PCs ship with it already on. Memory Integrity is on the same Core isolation page in Windows Security where you will find the stack protection toggle. Turn Memory Integrity on first.

Advertisement
⚠️WarningMicrosoft released a security update package for Windows 11, version 22H2.

KB5026372 Build 22621.1702 adds more drivers to a list of drivers that don't work with Kernel-mode Hardware-enforced Stack Protection. Your computer checks this list when you turn on this feature. If you have an older driver on that list, Windows may not let you turn the feature on until the driver is updated or removed.

📝ImportantYou must be signed in as an administrator to enable or disable this feature.

Not all drivers work with Kernel-mode Hardware-enforced Stack Protection. If your PC runs older hardware tools or utilities with their own drivers, check for updates from the vendor before you turn this on.

Option 1Use Windows Security App

Turn Kernel-mode Hardware-enforced Stack Protection On or Off

  1. Open Windows Security. You can search for it in the Start menu.
  2. Click Device security on the left side. Then click Core isolation details on the right side. You should now see the Core isolation page, with Memory Integrity and the stack protection setting.
windows 11 core isolation details link
windows 11 core isolation details link
  1. Find Kernel-mode Hardware-enforced Stack Protection and switch the toggle on or off, whichever you want. On supported PCs, Windows turns it on by default.

If the toggle is greyed out or the entry is missing, check three things. First, make sure Memory Integrity is on. Second, make sure your PC is running Windows 11 version 22H2 or later. Third, confirm your CPU is on the supported list above. If Windows says a driver is incompatible, update that driver and try again.

  1. [REQUIRES ADMIN] If prompted by UAC, click Yes to approve.
  2. Restart your computer to apply the change. The setting does not take effect until you do.

To undo the change, return to the same page, switch the toggle the other way, and restart again. If the PC has trouble after you turn it on, such as a driver that fails to load, turning the setting off is the first thing to try.

Advertisement
Windows 11 Settings panel for Kernel-mode Hardware-enforced Stack Protection
Windows 11 Settings panel for Kernel-mode Hardware-enforced Stack Protection

Option 2Use Registry Editor

Turn Kernel-mode Hardware-enforced Stack Protection On or Off Using Commands

This method works on both Home and Pro. It is useful if the Windows Security page won't let you change the setting, or if you want to script the change. Windows usually has the feature on by default on compatible PCs, so check the Windows Security page first.

  1. Right-click the Start button and select Terminal (Admin). [REQUIRES ADMIN]
  2. Click Yes if UAC asks for permission. A Terminal window opens with administrator rights.
  3. Run the command below.

Turn On Kernel-mode Hardware-enforced Stack Protection

If the command ran without an error, restart your computer so the change applies. This method does not skip the hardware and driver requirements above. Memory Integrity must still be running, and the CPU must support the feature. To undo it, switch the toggle off in Windows Security and restart.

🗝️Registry
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /v Enabled /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\KernelShadowStacks" /v Enabled /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\KernelShadowStacks" /v WasEnabledBy /t REG_DWORD /d 2 /f

Turn Off Kernel-mode Hardware-enforced Stack Protection

🗝️Registry
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\KernelShadowStacks" /v Enabled /t REG_DWORD /d 0 /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\KernelShadowStacks" /v WasEnabledBy /f

Summary

Kernel-mode Hardware-enforced Stack Protection helps guard the core of Windows 11 against malware. It uses a protected copy of return addresses to catch code that has been redirected. It needs a supported CPU, CPU virtualization and Memory Integrity. If you meet those requirements and no incompatible driver blocks it, turning it on takes a few clicks and a restart.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.

Advertisement

📚 Related Tutorials

Enhance Windows 11 Security with System Guard
Windows Enhance Windows 11 Security with System Guard
How to Change Registry Editor Font in Windows 11
Windows How to Change Registry Editor Font in Windows 11
How to Hide the Device Security Section in the Windows Security App on Windows 11
Windows How to Hide the Device Security Section in the Windows Security App on Windows 11
Protect Your Windows 11 with Microsoft Security
Windows Protect Your Windows 11 with Microsoft Security

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *