PC and Windows

What Is Virtualization-Based Security (VBS) in Windows?

VBS walls off part of memory so even the Windows kernel cannot touch it. What VBS and Memory Integrity do, what they cost in games and who requires them.

By the Elocarry team Support and product Last updated 4 min read
Quick answer
Virtualization-based security, or VBS, is a Windows feature that uses the processor's virtualization support to wall off a protected area of memory that even the Windows kernel cannot reach. Memory Integrity, also called HVCI, uses that area to check every kernel driver before it runs. It costs some games a little performance, and some anti-cheats now require it.
On this page 7 sections

Virtualization-based security is the newest of the Windows security features that games care about, and the least understood. Unlike Secure Boot or the TPM, it can cost you frame rate, which is why gamers have spent years arguing about whether to turn it off. Anti-cheats have now started requiring it, which turns that argument around.

What VBS is

Modern processors have hardware support for virtualization, the technology that lets one PC run several operating systems side by side. Windows uses the same technology for security.

With VBS on, Windows starts a small hypervisor underneath itself and uses it to create an isolated region of memory. The normal Windows kernel runs outside that region and cannot read or change anything inside it. Security features that need protecting, even from a compromised kernel, live inside.

On many new Windows 11 PCs, VBS is on out of the box.

What Memory Integrity does

Memory Integrity, also called HVCI (hypervisor-protected code integrity), is the VBS feature that matters most to games. It checks every driver before it is allowed to run in the kernel, from inside the protected region, so a compromised kernel cannot switch the check off. Unsigned drivers and drivers on Microsoft’s list of known vulnerable drivers are refused.

That directly affects cheats. Many cheats have relied on loading their own kernel drivers to get the same level of access as a kernel-level anti-cheat, or on abusing a legitimate driver with a security hole. Memory Integrity blocks both routes, which is exactly why anti-cheats have started to ask for it.

Who requires VBS

PlatformWhat it asks for
FACEIT, compared in VAC vs FACEITVBS and IOMMU, rolled out from April 2025 and enforced for all players above 3,000 Elo since August 2025
Riot Vanguard on-demand modeVBS and HVCI, along with Secure Boot, TPM 2.0 and IOMMU, on eligible Windows 11 PCs

FACEIT ties VBS to the IOMMU, the memory firewall that stops DMA cards reading game memory, because VBS is what lets Windows use the IOMMU reliably.

VBS and gaming performance

Running a hypervisor underneath Windows costs something. Microsoft has acknowledged that in some configurations Memory Integrity and the Virtual Machine Platform reduce gaming performance, and says gamers who want the most performance can turn them off while playing and back on afterwards, accepting that the PC is less protected while they are off.

How much it costs varies a lot by processor, game and settings. On many modern systems the difference is small.

There is now a catch: turning VBS off for frame rate can lock you out of platforms that require it. Check what your game or platform needs before you change anything.

How to check and change it

Check: press Windows and R, type msinfo32 and press Enter. The Virtualization-based security line in System Summary reads Running or Not enabled.

Memory Integrity: open Windows Security, go to Device security, choose Core isolation details and use the Memory integrity switch. Windows asks for a restart.

Virtual Machine Platform: search the Start menu for Turn Windows features on or off and tick or untick Virtual Machine Platform.

If the Memory Integrity switch refuses to turn on, Windows lists the incompatible drivers. They are usually old hardware utilities, and updating or uninstalling them clears the block.

VBS and your games

VBS is a trade between protection and a small amount of performance, and the right answer depends on what you play. If a platform such as FACEIT requires it, leave it on. If you are chasing frame rate in a game that does not, Microsoft’s own guidance allows switching it off while you play. If you are unsure what a game or build needs, ask support before changing security settings, rather than following a forum post.

Frequently asked questions

How do I check if VBS is running?

Press Windows and R, type msinfo32 and press Enter. In System Summary, the Virtualization-based security line reads Running or Not enabled. Memory Integrity has its own switch in Windows Security, under Device security and Core isolation details.

Should I turn off VBS for gaming?

Microsoft says gamers who want the most performance can turn off Memory Integrity and the Virtual Machine Platform while playing and turn them back on afterwards, at the cost of protection. Check first whether your game or platform requires them, because some anti-cheats now do.

Is Memory Integrity the same as VBS?

No. VBS is the protected environment. Memory Integrity, or hypervisor-protected code integrity, is one feature that runs inside it, checking kernel drivers. You can have VBS on with Memory Integrity off, but Memory Integrity needs VBS.

Why does Memory Integrity say I have incompatible drivers?

Some older drivers do things Memory Integrity does not allow, so Windows refuses to switch it on while they are installed. The list usually points at old hardware utilities. Updating or removing them clears it.

Topics Virtualization-based securityWindowsKernel levelSecure Boot

First published 6 October 2026. Last updated 6 October 2026. We update Wiki pages when the game, the anti-cheat or the build changes, not on a schedule.

Still stuck?

Ask Barry first: he answers in Discord around the clock and fixes most things on the spot. For billing or account questions, open a ticket and a person follows up.