GuideInformationBusiness ContinuityIT

Check prerequisites before enabling kernel hardware stack protection

How should a pilot for kernel hardware-enforced stack protection be prepared?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 1 min read
Executive summary

What you need to know

How should a pilot for kernel hardware-enforced stack protection be prepared?

Potentially affected

Use this review when evaluating the protection on a Windows system.

DSE recommendation

Inventory the hardware and installed drivers for the pilot system, and name the owner of any compatibility investigation.

Source facts

Microsoft describes kernel-mode hardware stack protection as a defense against return-oriented programming attacks on kernel stacks. The mechanism pairs kernel stacks with shadow stacks to check control-flow integrity. Virtualization-based security and hypervisor-enforced code integrity must be enabled before the feature is enabled; the documentation also specifies supported hardware and Windows prerequisites. Microsoft documentation.

Applicability

Use this review when evaluating the protection on a Windows system. Verify the exact operating-system, application, processor, and security prerequisites in the current source. Do not infer eligibility from the article’s placement within Windows Server documentation.

DSE recommendation

Inventory the hardware and installed drivers for the pilot system, and name the owner of any compatibility investigation. Record the starting state of the prerequisite protections. Agree on essential workload tests and a supported recovery procedure before enabling the feature. Select a representative system whose failure can be investigated without interrupting an unapproved production workload.

Verification

After the approved change and any requested restart, inspect the protection state and record whether it became active. Exercise the chosen applications and device functions. Preserve reported incompatibilities or unexpected failures with the relevant driver and system details. Expand only after the pilot owner accepts both the security-state evidence and the workload results.

Official references

Microsoft Learn: Kernel Mode Hardware-enforced Stack Protection. Source reviewed September 8, 2026.

Primary reference

Review the official source

Kernel Mode Hardware-enforced Stack Protection · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE