How To Turn Off Virtualization-Based Security (VBS) In Windows 10 And 11

How To Turn Off Virtualization-Based Security (VBS) In Windows 10 And 11

How to Properly Disable Virtualization-Based Security (VBS) in Windows ...

Virtualization-Based Security, or VBS, utilizes the Windows hypervisor to create an isolated memory region that protects critical system processes from unauthorized access, but it can be disabled via Windows Security settings, Group Policy, or UEFI/BIOS settings to resolve performance bottlenecks or compatibility issues. Disabling this feature requires administrative privileges and a subsequent system reboot to force the deactivation of the underlying hypervisor-protected code integrity (HVCI) protocols.


Pre-Procedure System Requirements and Security Considerations

Before initiating the removal of Virtualization-Based Security, you must evaluate the security posture of your environment. VBS acts as a foundational element for Windows Defender Credential Guard, Kernel Mode Code Integrity, and various sandbox environments. Disabling it significantly lowers the barrier for kernel-level exploits.



  • Essential Prerequisites:

  • Administrative access to the local machine or domain controller.

  • A clear understanding of the specific application or game compatibility error necessitating the change.

  • A system restore point or full disk backup to revert changes if system instability occurs.

  • Hardware-level virtualization (Intel VT-x or AMD-V) must remain enabled in the BIOS if you intend to use other virtualization tools like WSL2 or VMware.

  • Estimated Duration: 5 to 10 minutes, including two mandatory system reboots.

  • Required Tooling: Windows Security application, Local Group Policy Editor (for Professional/Enterprise editions), or command-line interface.

Step-by-Step Procedure to Disable VBS and HVCI



Step 1: Disabling Core Isolation via Windows Security

The most direct method for standard users involves toggling off Memory Integrity within the primary security interface.



  1. Click the Start button and type Windows Security, then select the app from the results.
  2. Navigate to Device Security in the left-hand pane.
  3. Locate the Core isolation details link and click it.
  4. Toggle the Memory integrity switch to the Off position.
  5. Close the application and restart your system. If the system fails to revert, proceed to the secondary methods below.

Warning: Attempting to disable these features while third-party antivirus software is actively managing kernel-level hooks may result in a non-bootable state. Ensure your security software is updated before proceeding.



Step 2: Utilizing the Group Policy Editor for Enterprise Persistence

If VBS re-enables itself automatically, the configuration is likely enforced by a Group Policy Object (GPO). This method is necessary for Windows Pro, Enterprise, and Education editions.



  1. Press Windows Key + R, type gpedit.msc, and press Enter to launch the editor.
  2. Navigate the directory tree to Computer Configuration > Administrative Templates > System > Device Guard.
  3. Locate the Turn On Virtualization Based Security setting in the right-hand panel.
  4. Double-click the entry and select the Disabled radio button.
  5. Click Apply and OK, then close the editor.
  6. Open Command Prompt as an administrator and run the command gpupdate /force to refresh the policy immediately.


Step 3: Removing UEFI-Locked VBS via Command Line

In some configurations, VBS is etched into the BCD (Boot Configuration Data) store, which requires a command-line intervention to strip the hypervisor launch parameters.



  1. Open Command Prompt as an administrator.
  2. Execute the command: bcdedit /set hypervisorlaunchtype off.
  3. Once the command returns the success message, restart the computer to allow the bootloader to apply the new parameters.
  4. To verify the status, run msinfo32 and check the System Summary under the Virtualization-based security entry. It should read Not enabled.

Come Disattivare il VBS (Virtualization Based Security) su Windows 11 ...

Come Disattivare il VBS (Virtualization Based Security) su Windows 11 ...

Technical Comparison of VBS Enforcement Methods



Method Scope of Influence Difficulty Level Persistence
Windows Security UI Local User Preference Low Temporary/User-Controlled
Group Policy Editor Machine-Wide / Registry Medium Persistent (unless overwritten)
BCD Command Line Bootloader/Kernel Level High System-Wide (Boot-Level)
Registry Edit Kernel/Driver Level Extreme Permanent (Hard-Coded)

Common Failure Scenarios and Operational Fixes



  • Scenario: Memory Integrity Remains "On" After Reboot. Root Cause: A conflict with incompatible drivers that require HVCI. Actionable Fix: Open the Windows Security settings, click "Review Incompatible Drivers," remove or update the flagged drivers, and repeat the disablement process.

  • Scenario: Option for VBS is Greyed Out. Root Cause: Windows is being managed by an organization or an active Mobile Device Management (MDM) profile (e.g., Intune). Actionable Fix: You must contact the IT administrator to have the policy lifted, or remove the work/school account linked to the device through Settings > Accounts > Access work or school.

  • Scenario: System Fails to Boot after Disabling. Root Cause: Residual security state mismatch in the UEFI secure boot database. Actionable Fix: Access the Recovery Environment by holding Shift while selecting Restart. Navigate to Troubleshoot > Advanced Options > Startup Settings and select "Disable Driver Signature Enforcement" to gain entry, then re-enable standard boot parameters.

Frequently Asked Questions



Will turning off VBS improve my gaming performance?

Yes, disabling VBS can yield a performance increase in CPU-bound gaming scenarios. Because VBS runs in a secure, isolated container, it imposes a performance tax on kernel operations, which can reduce frame rates by 5% to 15% in high-end titles.



Can I keep Virtualization-Based Security off permanently?

You can, but it is not recommended for devices used for sensitive data, such as banking or professional correspondence. Disabling it leaves your machine susceptible to credential theft, as Credential Guard will no longer isolate NTLM hashes and Kerberos tickets.



Does turning off VBS affect Windows Update or feature updates?

Generally, no. Windows Update will continue to function normally. However, some future Windows 11 feature updates may attempt to re-enable VBS as part of a default security hardening push, requiring you to repeat these steps occasionally.



Is VBS the same as Hardware Virtualization in BIOS?

No. Hardware virtualization (VT-x/AMD-V) is a CPU feature that allows the processor to run virtual machines. VBS is a Windows-specific software layer that consumes these hardware features to secure the OS kernel itself.

Optimize Your System Performance

Mastering your system's security architecture ensures you can balance the fine line between maximum protection and peak performance. If you continue to experience hardware throttling or compatibility errors after these adjustments, consult our advanced BIOS tuning guide to calibrate your CPU's virtualization throughput.


Virtualization-Based Security Won't Disable - Microsoft Q&A

Virtualization-Based Security Won't Disable - Microsoft Q&A

Read also: Marian price advocates for major changes in the local justice system