Microsoft Defender on Windows 11 runs through the Windows Security app, and that app includes several stronger protections that are frequently left disabled: Memory Integrity, Local Security Authority protection, Smart App Control, Controlled folder access and potentially unwanted app blocking. All five can be enabled from within Windows Security. Before Memory Integrity shows up, you may first have to enable virtualization in your BIOS. Enable them one at a time. That way, if an app stops working, you’ll know which setting is responsible.
Why these protections are often off
Virus scanning is only part of what Windows Security does. Some of its tougher safeguards ship disabled because they can block apps or cause compatibility issues, particularly with older drivers or software.
Getting a lot of Windows Security notifications doesn’t mean every important protection is running. These settings are most likely to be off on machines that were upgraded to Windows 11 instead of being freshly installed. You might also see a warning that your device may be vulnerable. That message only means the protection isn’t active. It doesn’t mean your data has been exposed.
Before you begin, make sure your PC is backed up, especially if you plan to change BIOS settings.
Turn on Memory Integrity
Memory Integrity is also known as Hypervisor-protected Code Integrity (HVCI). It relies on virtualization-based security to check drivers and other code before they can run in high-security areas of Windows. This helps keep malicious code out of the kernel, which is the core of the operating system.
- Open Windows Security.
- Go to Device security > Core isolation details.
- Turn on the Memory integrity toggle.
- Restart your PC.
- Return to Core isolation details and confirm that Memory integrity now shows On.
- Open Device Manager and look for any warning icons that point to a driver problem.
If Memory Integrity isn’t listed
A missing setting doesn’t necessarily mean your hardware can’t support it. Virtualization may simply be turned off in your BIOS.
Changing BIOS settings carries some risk. A mistake can leave your PC unable to boot properly, or unable to boot at all. Back up your PC first and change only the single setting described below.
- Open Task Manager and select the Performance tab.
- Check whether virtualization shows as enabled.
- If it’s disabled, restart into your BIOS.
- On an Intel PC, enable Virtualization Technology (VTx). On an AMD PC, enable SVM Mode. Leave every other BIOS setting as it is.
- Save your changes and restart into Windows.
- Return to Device security > Core isolation details. Memory integrity should now be listed as Off, and you can enable it using the steps above.
Turn on Local Security Authority protection
The Local Security Authority (LSA) is the part of Windows that handles sign-ins and keeps your login credentials in memory while you’re signed in. Attackers who steal credentials to sign in as you target it for that reason. LSA protection stops unsigned drivers and plug-ins from loading into it.
Once LSA protection is on, older security software and other components that aren’t properly signed may stop loading. Some users also see LSA protection errors after restarting. If something you depend on stops working, switch the toggle back off.
- Save your work. The change doesn’t take effect until you restart.
- Open Windows Security and go to Device security > Core isolation details.
- Under Memory integrity, find Local Security Authority protection and turn it on.
- Restart your PC.
Turn on Smart App Control
Smart App Control is stricter than an ordinary malware scan. It blocks any app Microsoft can’t verify as safe, including unsigned apps.
It has three settings: On, Off and Evaluation. In Evaluation mode, Windows works out whether it can protect you without getting in your way, then switches Smart App Control on or off by itself. On some PCs, the Evaluation option is greyed out.
For years, Smart App Control worked only on clean installs of Windows 11, and once you turned it off, the only way to turn it back on was to reinstall Windows. Microsoft changed this in 2026, so PCs that were upgraded to Windows 11 aren’t necessarily locked out anymore.
- Open Windows Security.
- Go to App & browser control > Smart App Control settings.
- Select On, or select Evaluation if it’s available.
Smart App Control will probably get in your way if you test a lot of apps or often download software from unfamiliar sources.
Turn on Controlled folder access
Controlled folder access stops apps that Windows doesn’t trust from changing files in protected folders such as Documents, Pictures and Videos. Ransomware has to change those files to lock them, so this setting defends against it.
- Open Windows Security.
- Go to Virus & threat protection > Manage ransomware protection.
- Turn on Controlled folder access.
- If you like, add other folders you want protected to the list on the same page.
Windows allows apps it considers safe, so most apps keep working normally. It can still stop you from saving files from an app you trust, which is why the feature is off by default. When this happens, Windows logs a protected folder access block. You may also see a suggestion to set up OneDrive so you can recover files.
Let a blocked app through
- Return to Virus & threat protection > Manage ransomware protection.
- Select Allow an app through Controlled folder access.
- Add the app that was blocked.
If you regularly use older or less common apps, you’ll probably need to do this from time to time.
Turn on potentially unwanted app blocking
Potentially unwanted apps (PUAs) aren’t always malware. They can still install other apps you didn’t ask for, show unexpected ads or cause other problems. Typical examples are the low-reputation toolbars and bloatware that come bundled with free installers.
According to Microsoft, this protection has been on by default since August 2021. You may still find it disabled, though, along with a warning that your device may be vulnerable.
- Open Windows Security.
- Go to App & browser control > Reputation-based protection settings.
- Turn on Potentially unwanted app blocking.
- Tick both boxes underneath it to block apps and block downloads.
A legitimate tool with little reputation can also be flagged, which matters if you download from less familiar sources. Windows lists everything it blocks in Protection history, so you can see what was stopped and why.
Frequently asked questions
Why is Memory Integrity missing from Core isolation details?
Usually because virtualization is turned off in the BIOS. Check the Performance tab in Task Manager. If virtualization is disabled, enable VTx (Intel) or SVM Mode (AMD) in the BIOS, and the setting should appear.
Does the “device may be vulnerable” warning mean I’ve been hacked?
No. The warning only means the protection isn’t turned on. It doesn’t mean your credentials or files have been exposed.
Why are these protections off by default?
Some of them can block apps or cause compatibility problems, particularly with older or unsigned software and drivers. If you enable them one at a time, it’s easier to find the cause when something breaks.
Can I use Smart App Control on a PC upgraded to Windows 11?
It used to require a clean install of Windows 11. Since a change Microsoft made in 2026, upgraded PCs aren’t necessarily locked out anymore.










STAY ALWAYS UP TO DATE