Windows Security does more than scan for viruses, but surprisingly, some of its stronger protections aren’t necessarily active on your PC by default. There’s usually a reason, since a few of them can block your apps or even cause compatibility problems.
I assumed the important ones were already taken care of because Windows Security constantly notifies me to take action. So I recently checked them all on my PC and noticed four were off by default, and one wasn’t even listed.
Memory Integrity
Hidden until I changed a BIOS setting
Memory Integrity, also called Hypervisor-protected Code Integrity (HVCI), uses virtualization-based security to run kernel-mode integrity checks on drivers and other code before they can run inside important, high-security parts of Windows. This, in turn, keeps malicious code out. You’ll find it under Windows Security -> Device security -> Core isolation details.
On my laptop, however, it wasn’t even listed at all. I initially thought my laptop’s hardware didn’t support it, but the problem was that virtualization was switched off in the BIOS.
So, I enabled Virtualization Technology in the BIOS, and Memory Integrity showed up, set to “Off.” I turned on the toggle, restarted, and it now shows as “On.” I also checked Device Manager to see if there are any driver issues and found no warning icons.
If it’s missing on your PC too, check the Performance tab in Task Manager to see if virtualization is enabled before assuming your hardware doesn’t support it. You may need to enable Virtualization Technology (VTx) on Intel and SVM Mode on AMD. Just change only that setting and leave everything else alone in the BIOS.
Back up your PC before making changes in the BIOS. Mistakes can disrupt or even stop your PC from booting.
LSA protection
One more layer for your login
The Local Security Authority is the part of Windows that handles sign-ins and keeps your login credentials in memory while you’re signed in. This makes it a prime target for credential-stealing attackers.
A stolen credential can let someone sign in as you. So, LSA protects you by preventing unassigned drivers and plug-ins from loading. It’s right under Memory Integrity on the same Core isolation details page.
Mine was off, with a warning under it that my device may be vulnerable. The warning doesn’t mean my credentials were exposed; it just means the protection wasn’t active. You need to save your work first because Windows won’t apply the settings until you restart.
You need to watch out for compatibility, though. Older security or other components that are not properly signed could stop loading once LSA is on. It is also not unusual to run into LSA protection errors after a restart, although I haven’t run into anything like that so far.
Smart App Control
Upgraded PCs used to be locked out
Smart App Control takes a stricter approach to apps than simply scanning for known malware. It blocks apps Microsoft cannot verify as safe, including unsigned ones. You can find it under App & browser control > Smart App Control settings, with three options: On, Off, and Evaluation.
In Evaluation mode, Windows learns whether it can protect you without getting in your way, then turns Smart App Control on or off itself. However, the Evaluation mode was greyed out on my PC.
For years, it was limited because it worked on clean installs of Windows 11, and once you turned it off, you couldn’t turn it back on without reinstalling. That meant people who had upgraded their PCs couldn’t simply switch it on later.
That’s no longer the case, as Microsoft introduced a change in 2026, so an upgraded PC like mine isn’t necessarily locked out anymore.
But it comes with a catch, especially if you test apps a lot. If you often download software from unfamiliar sources, it will likely get in your way.
Controlled folder access
Handy against ransomware, with one catch
Controlled folder access stops apps Windows does not trust from changing files in protected folders such as Documents, Pictures, and Videos, which is what ransomware needs to lock your files. You’ll find it in Virus & threat protection -> Manage ransomware protection. You can also add your own folders to the protected list there.
Most apps get through without issues, since Windows allows the ones it considers safe. Once I turned it on, it logged a protected-folder-access block while I was using Android DeX. It was marked as low severity. I also got a recommendation to set up OneDrive for file recovery.
The catch is that Controlled folder access can stop you from saving files from apps you trust, which is why it’s off by default. If that happens, you can just add the app under Allow an app through Controlled folder access. That’s something to keep in mind if you regularly use older or less common apps. That’s a fair trade for me to protect against ransomware.
Potentially unwanted app blocking
Microsoft says it’s on by default
Potentially unwanted apps (PUAs) aren’t necessarily malware, but they can install unwanted apps, display unexpected ads, or cause other problems. Those low-reputation toolbars and bloatware that ride along with free installers. You’ll find this setting in Apps & browser control -> Reputation-based protection settings.
Microsoft’s support page says PUA has been on by default since August 2021. So it was shocking that it was off on my PC, with the same warning that my device may be vulnerable, and I don’t know why. After enabling it, you should check the boxes below to block apps and downloads.
The only issue here is that a legitimate tool with little reputation can get flagged too. This is important if you download from less familiar sources. Windows actually keeps a list of what it blocks in Protection history, so you can review it.
Worth a look on your own PC
I suggest enabling these one at a time; if something breaks, you’ll know which setting caused it.
Everything has continued working after I enabled them on mine, and the Device Manager hasn’t flagged anything. Only the Controlled folder access blocking has been my intervention so far.
If you’ve had a Windows 11 laptop for years, especially if it was upgraded rather than freshly installed, open Windows Security and check these settings yourself. You may find that some of the protections you assumed were active aren’t.