# Check prerequisites before enabling kernel hardware stack protection

> How should a pilot for kernel hardware-enforced stack protection be prepared?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-014-check-prerequisites-before-enabling-kernel-hardware-stack-protection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:57+00:00
- Modified: 2026-09-08T18:17:13+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

How should a pilot for kernel hardware-enforced stack protection be prepared?

## Potentially affected

Use this review when evaluating the protection on a Windows system.

## DSE recommendation

Inventory the hardware and installed drivers for the pilot system, and name the owner of any compatibility investigation.

## Article

## Source facts

Microsoft describes kernel-mode hardware stack protection as a defense against return-oriented programming attacks on kernel stacks. The mechanism pairs kernel stacks with shadow stacks to check control-flow integrity. Virtualization-based security and hypervisor-enforced code integrity must be enabled before the feature is enabled; the documentation also specifies supported hardware and Windows prerequisites. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/kernel-mode-hardware-stack-protection).

## Applicability

Use this review when evaluating the protection on a Windows system. Verify the exact operating-system, application, processor, and security prerequisites in the current source. Do not infer eligibility from the article’s placement within Windows Server documentation.

## DSE recommendation

Inventory the hardware and installed drivers for the pilot system, and name the owner of any compatibility investigation. Record the starting state of the prerequisite protections. Agree on essential workload tests and a supported recovery procedure before enabling the feature. Select a representative system whose failure can be investigated without interrupting an unapproved production workload.

## Verification

After the approved change and any requested restart, inspect the protection state and record whether it became active. Exercise the chosen applications and device functions. Preserve reported incompatibilities or unexpected failures with the relevant driver and system details. Expand only after the pilot owner accepts both the security-state evidence and the workload results.

## Official references

[Microsoft Learn: Kernel Mode Hardware-enforced Stack Protection](https://learn.microsoft.com/en-us/windows-server/security/kernel-mode-hardware-stack-protection). Source reviewed September 8, 2026.

## Primary reference

- Name: Kernel Mode Hardware-enforced Stack Protection
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/kernel-mode-hardware-stack-protection
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check prerequisites before enabling kernel hardware stack protection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-014-check-prerequisites-before-enabling-kernel-hardware-stack-protection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
