Why is Memory Integrity greyed out or disabled?
Short answer: Memory Integrity (HVCI — Hypervisor-Protected Code Integrity — a security feature that puts the Windows kernel inside a virtualised container) is greyed out because one or more drivers on your system are flagged as incompatible. Windows 11 deliberately prevents enabling it until those drivers are removed or updated. The fix takes 10–20 minutes and requires no reinstallation.
How to enable Memory Integrity on Windows 11 26H1
Step 1: Check Device Security and read the driver list
Open Settings → Privacy & Security → Windows Security → Device Security → Core Isolation Details. Under the Memory Integrity toggle you will see either a green On (already enabled — nothing to do), a grey toggle with a warning, or a list of incompatible driver names. Click Review incompatible drivers to see the exact list. Note down the driver names and INF file names shown — you will need these in the next step. Common culprits in India: older Realtek audio drivers bundled with OEM images, VPN tap-adapters (NordVPN, ExpressVPN older versions), antivirus kernel modules from pre-2022 installations, and printer or scanner drivers from legacy peripherals.
Step 2: Update or remove flagged drivers
For each flagged driver: open Device Manager (right-click Start → Device Manager), find the device matching the driver name, right-click → Update driver → Search automatically. If an updated driver is found, install it. If the device is legacy hardware you no longer use, right-click → Uninstall device and check "Delete the driver software". For third-party apps (VPN, antivirus), update the app itself to the latest version — modern versions ship HVCI-compatible drivers. After each removal or update, recheck the Device Security page — the driver list should shrink. Repeat until the list is empty.
Step 3: Enable Memory Integrity and reboot
Once the incompatible drivers list is clear, toggle Memory Integrity to On. Windows will prompt you to restart. After rebooting, return to Core Isolation Details and confirm the toggle is green. If you see a BSOD (blue screen — system crash) on reboot, do not panic: hold Shift at the Windows sign-in screen and click Restart → Troubleshoot → Advanced Options → Startup Settings → Restart → press 4 (Safe Mode). Then go back to Core Isolation and toggle Memory Integrity off. This recovers the machine safely so you can identify the remaining conflicting driver.
Step 4: The India angle — OEM bloatware drivers are the #1 culprit
In India, most Windows 11 laptops shipped by HP, Dell, and Lenovo between 2020 and 2023 came pre-loaded with OEM utility software that includes its own kernel-level drivers — HP Support Assistant, Dell SupportAssist, Lenovo Vantage background services, and third-party antivirus trials bundled by the manufacturer. These bundled drivers are the single largest cause of HVCI conflicts seen in Indian repair shops. The fix is to update each OEM utility app to its latest version (not just the driver — the app ships the driver). See also our guide on updating BIOS on HP, Dell, and Lenovo — a BIOS update often brings updated firmware-signed drivers that resolve HVCI conflicts as a side effect. After enabling HVCI, also review our TPM 2.0 enablement guide to ensure the full Windows 11 security baseline is active on your machine.
When to call a laptop repair service
When DIY ends
Seek professional help if: the Device Security page shows no driver list but HVCI still will not toggle on, you get a repeated BSOD even in Safe Mode after disabling HVCI, or you are on a corporate machine where driver changes require IT approval and you need a compliant HVCI-ready build.
Typical cost in India
Windows 11 security configuration service (HVCI + TPM + Secure Boot audit): ₹500–₹900. Full OS reinstall with clean driver set and HVCI enabled: ₹1,200–₹1,800. Doorstep visit charge: ₹149, No Fix No Fee.
A note from the LRW Engineer Team
HVCI is not just a security checkbox — it is one of the most effective defences against the rootkit attacks that have become common in India's corporate laptop segment. 80% of the kernel-level malware we encounter in enterprise laptops could have been blocked if HVCI had been active. Enable it once, keep your drivers current, and you will likely never need data recovery for a kernel infection.