Windows 11 will not show incompatible drivers

Anonymous
2023-03-23T21:22:01+00:00

In new windows 11 up to date as of writing this. Core isolation memory integrity does not work and will not turn on. Every time I scan for incompatible drivers, none are listed. Checked the windows update, the system is up to date, and no errors in device drivers were found. All drivers appear up to date. BIOS most recent available (the same driver that was installed prior to this error occurring. None of the threads seem to address this, only ones where the driver is known. The DG readiness tool is not user-friendly for everyday users. Need a solution that can be done at home without having to be an IT guru or MSCE certified. It will not let me upload the screenshot or picture, keep getting errors in that as well.

Windows for home | Windows 11 | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

164 answers

Sort by: Most helpful
  1. Anonymous
    2024-09-10T23:15:34+00:00

    Well that's good to know. I support many client machines and I never saw the issue on a new Dell - same with another fellow who seemed to only see this on older migrated 10->11 Dells and I have a good idea why. But you are the first person reporting that no driver is listed in a fairly new Windows 11. I'd still venture to guess it is Dell installing an old addon from old software whose certificate has not been updated. Can you post the output of:

    driverquery /V

    here?

    Thanks,

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-09-10T22:03:56+00:00

    This is somewhat risky/ill-advised as follows: you are allowing drivers to remain which do not meet the stringent tests Microsoft makes to ensure all drivers meet the requirements those tests check for. With Memory integrity protection, kernel memory pages are only made executable after passing code integrity checks inside the secure runtime environment, and executable pages themselves are never writable.  Thus you leave yourself with some drivers that don't meet these requirements. And that means some viruses who look for these drivers, will try to hide themselves in modified code pages or data pages turned into code pages where code was not checked. The good news about turning it on is that no driver now or moving forward will be able to be installed if it doesn't meet those checks. A better solution would be to identify the bad drivers and remove them but as I mentioned in the Dell Community, this requires use of a deprecated Microsoft tool and I asked Dell to reach out to me but they don't seem to care. This seems to be a problem for older Dell computers upgraded from Windows 10 to 11 using Dell-related drivers.

    Now here is what ChatGPT 4.o says:

    Changing the HypervisorEnforcedCodeIntegrity (HVCI) setting to 1 in the Windows registry can pose significant risks, especially if done as a hack to bypass proper enablement processes. Here are the risks and considerations associated with this approach:

    System Instability and Crashes:

    • Enabling HVCI without addressing incompatible or unsigned drivers can cause system crashes (blue screen of death - BSOD) or instability because incompatible drivers may not load correctly or at all.
    • Critical drivers that are required for booting or hardware functionality may be blocked, leading to the inability to boot into Windows.

    Incompatibility with Older or Custom Drivers:

    • HVCI enforces a strict validation of drivers, ensuring they are signed and comply with Microsoft's Kernel Mode Code Signing (KMCS) policies.
    • Many older or custom drivers, especially those not updated to meet modern security standards, will fail to load, rendering certain hardware or applications unusable.

    No Error Information:

    • If you are trying to enable Code Integrity and it fails without listing the problematic drivers, simply changing the registry may not resolve the underlying issues. It can lead to difficult debugging, as you'll lack insight into which drivers are causing the failure.
    • Driver validation tools should be used to identify incompatible drivers before enabling HVCI.

    Security Implications:

    • If HVCI is hacked on without proper implementation, it could be incompletely enforced, leaving security vulnerabilities that could be exploited by malware or other malicious code.
    • If incompatible drivers are bypassing checks, malicious actors may take advantage of this to execute unauthorized code at the kernel level.

    Hardware and Firmware Incompatibilities:

    • HVCI relies on virtualization-based security (VBS), which in turn depends on specific hardware features (like CPU virtualization extensions).
    • If your system's firmware or hardware does not fully support VBS or HVCI, changing the registry value to force enablement may result in hardware conflicts, leading to non-functional virtualization features and even hardware failure.

    Recovery Complexity:

    • If the system fails to boot after enabling HVCI through the registry, recovery might involve booting into safe mode or using system recovery tools to revert the changes. This can be difficult, especially if drivers required for recovery are blocked by HVCI.
    • Test Compatibility First: Use Microsoft's Device Guard and Credential Guard Readiness Tool to check compatibility before enabling HVCI.
    • Update Drivers: Ensure all drivers are updated to the latest versions and compatible with Kernel Mode Code Integrity requirements.
    • Use Group Policy or Settings: Where possible, use the official settings via Windows Defender Security Center or Group Policy Editor to enable HVCI, rather than directly modifying the registry.

    By forcing HVCI through registry edits, you risk breaking your system in ways that might be difficult to recover from, and you may not achieve the desired security benefits if done improperly.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-06-08T16:00:47+00:00

    see https://www.dell.com/community/en/conversations/inspiron-desktops/cannot-turn-on-memory-integrity/6663fa3f9d31ec38a7cdbaba and keep an eye out for a solution. Ignore the disingenuous first reply there.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-12-07T13:43:28+00:00

    I also have had this problem for over a year. I was on chat with MS tech support, and basically told me to do a Windows repair. That did not work, and when I escalated again, no response. It seems tech support solutions always come down to a clean reinstall...but this issue came about after their updates. The tech did admit it was a known problem, but then also said that a fix was implemented in some update around March 2023.

    I will add screenshots below (not like you do not already believe me). It is just annoying that you get this alert that you are vulnerable because of an incompatible driver, but then no driver is listed. I was patient thinking that an update would happen at some point, but it has been too long.

    I would try some of these solutions like editing the Registry, but they do not seem to fix the problem. My PC is workings fine, so I do not want to start causing other problems, just to remove some flag.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2023-07-27T13:37:30+00:00

    Yes it's probably Dell, but they won't do anything either. They are all just acting like it's not their problem!

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments