Windows Security, the app that runs Microsoft Defender on Windows 11, has several stronger protections that often aren’t switched on: Memory Integrity, Local Security Authority protection, Smart App Control, Controlled folder access and potentially unwanted app blocking. You can turn each one on from inside Windows Security. Memory Integrity may also need virtualization enabled in your BIOS before it appears. Turn them on one at a time so you can tell which one caused the problem if an app stops working.
Why these protections are often off
Windows Security does more than scan for viruses. Some of its stronger protections are off by default because they can block apps or cause compatibility problems, especially with older software or drivers.
Frequent Windows Security notifications don’t mean everything important is already on. PCs that were upgraded to Windows 11 rather than freshly installed are the most likely to have these settings off. You may also see a warning that your device may be vulnerable. That warning means the protection isn’t active. It doesn’t mean your data has been exposed.
Before you start, check that you have a backup of your PC, especially if you’ll be changing BIOS settings.
Turn on Memory Integrity
Memory Integrity, also called Hypervisor-protected Code Integrity (HVCI), uses virtualization-based security to check drivers and other code before they’re allowed to run in high-security parts of Windows. This helps keep malicious code out of the kernel, the core of the operating system.
- Open Windows Security.
- Go to Device security > Core isolation details.
- Turn on the Memory integrity toggle.
- Restart your PC.
- Go back to Core isolation details and check that Memory integrity now shows as On.
- Open Device Manager and look for warning icons that would point to a driver problem.
If Memory Integrity isn’t listed
If the setting doesn’t appear at all, your hardware may still support it. Virtualization may be switched off in your BIOS.
Changing BIOS settings carries some risk. A mistake can stop your PC from booting properly or at all, so back up your PC first and change only the one setting below.
- Open Task Manager and select the Performance tab.
- Check whether virtualization shows as enabled.
- If it’s disabled, restart into your BIOS.
- Enable Virtualization Technology (VTx) on an Intel PC or SVM Mode on an AMD PC. Leave every other BIOS setting as it is.
- Save and restart into Windows.
- Go back to Device security > Core isolation details. Memory integrity should now be listed as Off, and you can turn it on using the steps above.
Turn on Local Security Authority protection
The Local Security Authority (LSA) is the part of Windows that handles sign-ins and keeps your login credentials in memory while you’re signed in. That makes it a target for attackers who steal credentials to sign in as you. LSA protection stops unsigned drivers and plug-ins from loading into it.
Older security software or other components that aren’t properly signed may stop loading once LSA protection is on. Some people also see LSA protection errors after the restart. If something you rely on stops working, turn the toggle back off.
- Save your work. Windows won’t apply the change until you restart.
- Open Windows Security and go to Device security > Core isolation details.
- Find Local Security Authority protection under Memory integrity and turn it on.
- Restart your PC.
Turn on Smart App Control
Smart App Control is stricter than a normal malware scan. It blocks apps Microsoft can’t verify as safe, including unsigned ones.
It has three settings: On, Off and Evaluation. In Evaluation mode, Windows works out whether it can protect you without getting in your way, then turns Smart App Control on or off by itself. On some PCs, Evaluation is greyed out.
For years, Smart App Control only worked on clean installs of Windows 11. Once you turned it off, you couldn’t turn it back on without reinstalling Windows. Microsoft changed this in 2026, so a PC that was upgraded to Windows 11 isn’t necessarily locked out anymore.
- Open Windows Security.
- Go to App & browser control > Smart App Control settings.
- Choose On, or choose Evaluation if it’s available.
If you test a lot of apps or often download software from unfamiliar sources, Smart App Control will likely get in your way.
Turn on Controlled folder access
Controlled folder access stops apps Windows doesn’t trust from changing files in protected folders such as Documents, Pictures and Videos. Ransomware needs to change those files to lock them, so this setting protects against it.
- Open Windows Security.
- Go to Virus & threat protection > Manage ransomware protection.
- Turn on Controlled folder access.
- Add any other folders you want protected to the list on the same page if you like.
Windows lets through apps it considers safe, so most apps work normally. It can still stop you saving files from an app you trust, which is why it’s off by default. When that happens, Windows logs a protected folder access block. You may also see a suggestion to set up OneDrive so you can recover files.
Let a blocked app through
- Go back to Virus & threat protection > Manage ransomware protection.
- Select Allow an app through Controlled folder access.
- Add the app that was blocked.
If you often use older or less common apps, expect to do this now and then.
Turn on potentially unwanted app blocking
Potentially unwanted apps (PUAs) aren’t always malware, but they can install other apps you didn’t ask for, show unexpected ads or cause other problems. Think of the low-reputation toolbars and bloatware that come bundled with free installers.
Microsoft says this protection has been on by default since August 2021, but you may still find it off, with a warning that your device may be vulnerable.
- Open Windows Security.
- Go to App & browser control > Reputation-based protection settings.
- Turn on Potentially unwanted app blocking.
- Check both boxes below it to block apps and block downloads.
A legitimate tool with little reputation can get flagged too, which matters if you download from less familiar sources. Windows lists everything it blocks in Protection history, so you can check what was stopped and why.
Frequently asked questions
Why is Memory Integrity missing from Core isolation details?
Virtualization is often switched off in the BIOS. Check the Performance tab in Task Manager. If virtualization is disabled, enable VTx (Intel) or SVM Mode (AMD) in the BIOS and the setting should appear.
Does the “device may be vulnerable” warning mean I’ve been hacked?
No. It means the protection isn’t turned on. It doesn’t mean your credentials or files have been exposed.
Why are these protections off by default?
Some of them can block apps or cause compatibility problems, especially with older or unsigned software and drivers. Turning them on one at a time makes it easier to find the cause if something breaks.
Can I use Smart App Control on a PC upgraded to Windows 11?
It used to need a clean install of Windows 11. Since a change Microsoft made in 2026, upgraded PCs aren’t necessarily locked out anymore.
