How to Enable or Disable Memory Integrity Core Isolation in Windows 11
Memory Integrity is a Windows 11 security setting inside Core Isolation (a tool that keeps core parts of your operating system away from malicious code) that stops malware from reaching the most sensitive areas of your PC. It blocks hidden threats from taking over your system by making sure every driver running on version 22H2 or newer is safe and trusted.
Managing this feature can sometimes feel tricky when Windows blocks the change or shows confusing errors about broken drivers. You can safely turn it on or off through the Windows Security app to keep your system safe while letting your favorite apps and hardware run normally.
Open the Windows Security app, click Device security, select Core isolation details, and switch the Memory integrity toggle to On or Off. Restart your computer after making your choice to finish changing the setting.
What is Core Isolation and Memory Integrity?
Core isolation and memory integrity are built-in Windows 11 security features that protect your computer by creating a safe, isolated area of system memory. Core isolation separates normal operating processes from your computer hardware, while memory integrity specifically stops malicious software from attacking low-level system drivers.
Memory Integrity is a security setting inside Core Isolation on Windows 11. Memory Integrity protects driver software, which consists of small programs that help Windows talk to your computer hardware like graphics cards and printers. If a bad actor tries to put harmful code into a driver, Memory Integrity blocks that harmful code right away. This protection stops malicious code from taking over your computer system.
While this setting offers strong protection, older software or specialized hardware drivers sometimes fail to work with it. If your computer relies on one of these older drivers, Windows blocks the older driver from loading. This block can cause your favorite programs or devices to stop working properly.
How to Check If Memory Integrity Is Enabled
Open the Windows Security app and check your device security settings to see if Memory Integrity is active. Click the Start button , type Windows Security, open the app, click Device security, and select Core isolation details to view the current status.
- Click the Start button on your taskbar and type Windows Security.
- Click the Windows Security app from the search results.
- Click on Device security on the left-hand menu.
- Under the Core isolation section, click the Core isolation details link.
- Look at the toggle switch next to Memory integrity to see if it is turned On or Off.
How to Enable Memory Integrity in 🪟 Windows 11
You can enable memory integrity in Windows 11 by opening the Windows Security app, going to device security settings, opening the core isolation details, and switching the memory integrity toggle to the on position. This turns on extra protection to stop harmful software from getting into your system drivers.
- Open the Windows Security app from your Start menu search.
- Select Device security from the side menu.
- Click on Core isolation details.
- Click the toggle switch under Memory integrity to move it to the On position.
- If a User Account Control prompt appears asking for permission to make changes, click Yes. (Note: This step requires administrator privileges).
- Restart your computer when Windows prompts you to finish turning on the feature.
How to Disable Memory Integrity in 🪟 Windows 11
You can disable memory integrity in Windows 11 by opening the Windows Security app, clicking device security, opening the core isolation details, and turning off the memory integrity toggle switch. People usually turn this setting off when an older game, app, or piece of hardware will not run properly while it is active.
- Open the Windows Security app by searching for it in your Start menu.
- Click on Device security on the left side of the window.
- Click on the Core isolation details link.
- Click the toggle switch under Memory integrity to move it to the Off position.
- If a User Account Control prompt appears asking for permission, click Yes. (Note: This step requires administrator privileges).
- Restart your computer to apply the changes.
How to Fix Common Problems When Memory Integrity Won't Turn On
You can fix common problems when memory integrity will not turn on by checking your system for incompatible drivers that block the security setting. Windows Security usually shows a review incompatible drivers link when this happens, letting you see the exact files you need to update or remove from your computer.
When incompatible software blocks Memory Integrity from turning on in Windows 11, Windows Security provides a helpful link called Review incompatible drivers. Clicking the Review incompatible drivers link shows you a list of specific software files that block Memory Integrity from turning on. To fix the issue, you need to remove the incompatible files or update the software.
- Open the Windows Security app and go to Device security, then Core isolation details.
- Click on Review incompatible drivers to see the list of problematic software.
- Note the names of the drivers or companies listed. Common culprits include older security tools like Trusteer Rapport, older printer software, or niche gaming accessories.
- Open your Windows settings, go to Installed apps, find the software associated with those drivers, and uninstall it completely.
- If you cannot find the app in your settings, you may need to delete the specific driver file manually from your system folders.
- Restart your computer and try turning Memory Integrity back on using the steps in the previous section.
Alternative Ways to Manage Memory Integrity (Group Policy and Registry)
You can manage memory integrity using alternative methods like local group policies or manual registry adjustments if the main security menu is locked or unavailable. These advanced methods let system administrators and home users control the security feature directly through system files and policy settings.
If you need to make these changes using the Windows Registry Editor directly, you can navigate to the correct location to control virtualization-based security settings. Alternatively, you can use the Group Policy Editor on professional versions of Windows 11 to enforce this setting.
To use the local Group Policy Editor:
- Press the Windows Key + R on your keyboard to open the Run dialog box.
- Type gpedit.msc and press Enter. (Note: This step requires administrator privileges and is only available on Windows Pro or Enterprise editions).
- In the window that opens, use the left folder tree to go to Computer Configuration, then Administrative Templates, then System, and finally Device Guard.
- Double-click on the setting named Turn On Virtualization Based Security.
- Select Enabled, and then make sure the options below it are configured to turn on Secure Boot and Direct Memory Access Protection, along with virtualization-based protection of code integrity.
- Click Apply and then OK, and restart your computer.
Advanced Troubleshooting: What to Do When Files Are Left Behind
Windows keeps blocking the security setting if it detects these leftover files, so you must find and remove the exact file names shown in the security warnings.
To fix this stubborn issue, you need to find the exact file name shown in the security warning and delete it from your system storage manually. You will typically find these stubborn driver files located in the system folders where Windows stores hardware instructions. Deleting these leftover files allows Windows Security to finally turn on Memory Integrity without any more error messages.
Summary
What you should see now: Memory Integrity runs with your drivers protected against malicious code. If a future feature update or driver installation disables the feature, return to the Core isolation settings in the Windows Security app to re-enable it.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!