What you need to know
How should a pilot for kernel hardware-enforced stack protection be prepared?
Potentially affected
Use this review when evaluating the protection on a Windows system.
DSE recommendation
Inventory the hardware and installed drivers for the pilot system, and name the owner of any compatibility investigation.
Source facts
Microsoft describes kernel-mode hardware stack protection as a defense against return-oriented programming attacks on kernel stacks. The mechanism pairs kernel stacks with shadow stacks to check control-flow integrity. Virtualization-based security and hypervisor-enforced code integrity must be enabled before the feature is enabled; the documentation also specifies supported hardware and Windows prerequisites. Microsoft documentation.
Applicability
Use this review when evaluating the protection on a Windows system. Verify the exact operating-system, application, processor, and security prerequisites in the current source. Do not infer eligibility from the article’s placement within Windows Server documentation.
DSE recommendation
Inventory the hardware and installed drivers for the pilot system, and name the owner of any compatibility investigation. Record the starting state of the prerequisite protections. Agree on essential workload tests and a supported recovery procedure before enabling the feature. Select a representative system whose failure can be investigated without interrupting an unapproved production workload.
Verification
After the approved change and any requested restart, inspect the protection state and record whether it became active. Exercise the chosen applications and device functions. Preserve reported incompatibilities or unexpected failures with the relevant driver and system details. Expand only after the pilot owner accepts both the security-state evidence and the workload results.
Official references
Microsoft Learn: Kernel Mode Hardware-enforced Stack Protection. Source reviewed September 8, 2026.
Review the official source
Kernel Mode Hardware-enforced Stack Protection · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE