MiniTool gives a full guide to Core isolation, including the Core isolation definition, its prerequisites, and methods to enable it. Additionally, it lists common Core isolation-related issues and how to resolve them.

Quick Answer

Core Isolation is a hardware-supported security feature to protect critical system processes by isolating them in memory. Its key component is Memory Integrity, which can prevent malicious code. You can enable Core Isolation by going to Windows Security > Device Security > Core Isolation details.

What Is Core Isolation?

According to Microsoft, Core isolation is a Windows security feature in Windows 10/11. It uses virtualization-based security (VBS) to isolate critical system processes in memory, protecting them from malware and unauthorized access.

On the Core isolation page, there are many options, such as:

Note:
The options listed on the Core isolation page vary depending on the Windows version you’re running and the hardware components installed.

Memory Integrity (HVCL)

This is the most common setting. It uses virtualization to prevent malicious code from hijacking high-security processes. It ensures that only verified and signed drivers can access the kernel.

Tips:
If Memory integrity can't be turned on, the Review incompatible drivers link will appear to help you identify and remove outdated or unsigned drivers that prevent the feature from working.

Kernel-Mode Hardware-Enforced Stack Protection

This feature uses CPU capabilities (like Intel CET) to protect system memory from ROP (Return-Oriented Programming)-based attacks and unauthorized modifications.

Local Security Authority (LSA) Protection

This feature helps prevent credential theft by ensuring that only authorized processes can access sensitive login credentials.

Microsoft Vulnerable Driver Blocklist

It automatically prevents known-malicious drivers from loading on your system.

Microsoft Defender Credential Guard

It isolates secrets so that only privileged system software can access them.

How to Fix Core Isolation Blocked by ew_usbccgpfilter.sys?
How to Fix Core Isolation Blocked by ew_usbccgpfilter.sys?

You may meet the “core isolation blocked by ew_usbccgpfilter.sys” issue on Windows 11/10 when using a laptop/PC. Here are the fixes.

Read More

Should You Turn on Core Isolation?

In Windows 11/10, enabling Core Isolation is recommended because it can add an extra layer of protection against malware. However, you should disable this feature in some situations. Check the following table to decide whether to turn it on.

ScenarioRecommendation
Normal Windows usersEnabled (for strong system security)
PCs used for work or sensitive dataEnabled
Gaming PCs experiencing performance problemsDisabled
Older PCs or systems with driver issuesDisabled

Core Isolation Requirements for Windows 10/11

Before enabling it, make sure your PC meets these requirements:

  • UEFI Mode: Your system must be in UEFI mode, not Legacy or CSM (Compatibility Support Module)
  • Virtualization Enabled: Intel VT-x or AMD-V must be turned on in BIOS/UEFI.
  • TPM 2.0: A Trusted Platform Module (version 2.0) is required to store security keys.
  • Secure Boot: Secure Boot must be enabled.
  • DEP (Data Execution Prevention): This must be supported and typically turned on in the BIOS.
  • Compatible Drivers: Every driver on your system must be compatible with Hypervisor-Protected Code Integrity (HVCI).

Back Up Your Data Before Changing Security Settings

Changing security settings, such as enabling Core Isolation, may affect system stability. Creating a backup beforehand can help prevent data loss if unexpected issues occur.

To achieve that, it is highly recommended to use MiniTool ShadowMaker. This PC backup software can help you perform Windows 10 backup and Windows 11 backup easily.

Step 1. Download and install MiniTool ShadowMaker on your computer. Then, launch it to enter the main interface.

MiniTool ShadowMaker TrialClick to Download100%Clean & Safe

Step 2. Select Backup from the left panel, go to SOURCE, and select Folders and Files.

The interface of MiniTool ShadowMaker with selected Folders and Files.

Step 3. Choose the files that you want to back up and click OK.

Step 4. Access DESTINATION, choose a storage path, and click OK.

Step 5. Click Back Up Now and OK sequentially to execute the file backup.

The interface of MiniTool ShadowMaker with selected Back Up Now and OK.
How to Fix the Wdcsam64.sys Memory Integrity Error on Win11/10
How to Fix the Wdcsam64.sys Memory Integrity Error on Win11/10

When you try to open memory integrity on Windows 11/10, you may meet the wdcsam64.sys memory integrity error. There are some solutions for you.

Read More

How to Enable Core Isolation Memory Integrity

After ensuring your computer meets all the prerequisites for Core isolation and doing a backup of important data, enable Core isolation using the two methods:

  • Via Windows Security
  • Via Registry Editor

Here’s the detailed breakdown:

Method 1. Via Windows Security

Enabling Core isolation via Windows Security is the easiest way. Here’s the guide:

Step 1. Press Win + S to open Search, type windows security, and press Enter.

Step 2. In the prompted window, select Device security.

Step 3. Find Core isolation in the new page and click Core isolation details.

Step 4. Toggle on the switch under Memory integrity.

The Core isolation page in Windows Security with circled enabled Memory integrity.

Step 5. Restart your PC to apply the change.

To disable this feature, toggle the Memory integrity switch off on this page.

Method 2. Via Registry Editor

Additionally, Registry Editor can also help you enable Core isolation.

Follow the instructions:

Step 1. Press Win + R to open Run, type regedit, and click OK.

Step 2. In Registry Editor, navigate to this path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios

Step 3. Right-click Scenario and select New > Key, name it HypervisorEnforcedCodeIntegrity.

Step 4. Right-click the newly created key, choose New > DWORD (32-bit) Value, and then name it Enabled.

Step 5. Double-click the Enabled value, set the Value data to 1, and then click OK to save the change.

Tips:
If you set the Value data of Enabled to 0, Core isolation will be disabled.
The Edit DWORD (32-bit) Value window of Enabled in Registry Editor with selected OK.

Step 6. Restart your PC. Then, Core isolation is enabled successfully.

You may encounter problems when enabling or using Core isolation. Below are the most common issues and practical solutions.

Incompatible Drivers

Memory integrity incompatible drivers appear when Windows detects kernel-mode drivers that do not meet security requirements. This usually occurs during system updates, driver installations or updates, or when enabling Memory integrity in Windows Security.

To fix this issue, take the following steps:

  • Identify the Incompatible Driver: Go to Windows Security > Device security > Core isolation details. Then, click Review incompatible drivers. Note the driver’s name and path.
  • Update the Driver: Go to the manufacturer’s official website, download the latest and compatible driver.
  • Remove the OEM Driver Package via PowerShell: Open PowerShell as Administrator. Run pnputil /enum-drivers to list drivers. Next, identify the oemxx.inf file associated with the incompatible driver. Then, run pnputil /delete-driver oemxx.inf /uninstall.
  • Remove Hidden Devices: Open Device Manager, click View > Show hidden devices, check for yellow warning icons, and uninstall broken drivers.
  • Clean Boot: If you cannot identify the software, perform a clean boot to see if a third-party service is the cause.

If the incompatible driver isn’t essential, uninstall the driver.

Performance Reduction

If you find a performance reduction after enabling Core isolation, the most effective solution is to disable Memory integrity. In addition to that, try the following tips to fix this issue:

  • Update Device Drivers: Incompatible or outdated drivers can cause conflicts when Core isolation is on. Thus, check for updates of your drivers. If there are available updates, install them.
  • Use Group Policy: If the Memory integrity setting is grayed out, open Group Policy Editor, navigate to Computer Configuration > Administrative Templates > System > Device Guard, double-click Turn on Virtualization Based Security, select Enabled, click Apply, and OK. Next, restart the PC.
  • Check for Malware: If malware is interacting with the kernel, Memory Integrity may work harder. Run a full virus scan in Windows Security to fix the issue.

Core Isolation Turned Off by Itself

If Memory integrity is off by itself, it may be caused by various reasons, including incompatible drivers, disabled Virtualization, conflicting software, and corrupted system files.

To troubleshoot this issue, try the following methods:

  • Identify and Remove Incompatible Drivers: Go to the Review incompatible drivers page to identify the culprits and update or uninstall them.
  • Enable Virtualization in BIOS/UEFI: Restart your computer and enter BIOS. Enable Intel VT-x or AMD-V.
  • Run System File Checker (SFC): Run Command Prompt as administrator, type sfc /scannow and press Enter to fix corrupted system files.
  • Update or Reinstall Drivers: Open Device Manager, expand the category, and then update or reinstall outdated or incompatible drivers.
  • Reset Windows Security App: On Windows 11, go to Settings > System > System components and find Windows Security. Then, click the three dots next to it, click Advanced options, and then click Reset.
  • Check for Conflicting Software: Temporarily disable third-party antivirus software to check if they conflict with Core isolation.
Turn on Memory Integrity Causing BSOD? 3 Top Fixes
Turn on Memory Integrity Causing BSOD? 3 Top Fixes

Are there any solutions to fix the turn on memory integrity causing BSOD error? Try the three solutions in this post.

Read More

I’ve been confused about Core isolation and its features, but this post provides a clear guide on what it is, how to manage it, and how to troubleshoot related issues. I wanted to share it.Click to Tweet

Bottom Line

Core isolation is a Windows 10/11 security feature that protects core system processes. Although it enhances security, it may slightly reduce performance in some apps and games.

For data security, it is necessary to back up your important data via MiniTool ShadowMaker before enabling this feature on your PC.

In terms of issues with MiniTool software, contact us at [email protected].

Core Isolation FAQ

Should Core Isolation be on for gaming?
Most PCs can keep Core Isolation enabled. If you experience FPS drops (about 5% to 15%) or compatibility problems, disable it.
Should I turn off virtualization for gaming?
Disabling CPU virtualization or Virtualization-Based Security can improve gaming performance and reduce input latency, especially on lower-end hardware. However, it is not recommended, as doing so weakens the system’s protection against modern malware.
Why does Windows say Memory Integrity cannot be turned on due to incompatible drivers?
This error usually occurs in Windows 11/10 when the system detects an unsigned or outdated driver. It is commonly associated with legacy printers, USB drives, network adapters, and RGB controllers.
What is the difference between Core Isolation and Memory Integrity?
Core Isolation is the security framework that uses virtualization to protect core system processes. Memory Integrity is a specific feature inside Core Isolation that blocks malicious mode from entering high-security processes.
  • linkedin
  • reddit