Tag: HVCI

  • Riot Vanguard finally drops its controversial always-on requirement for anti-cheat — new on-demand mode requires a strict Windows 11 security stack

    Riot Lets Gamers Take Back Control of Anti-Cheat with On-Demand Mode

    The anti-cheat world is undergoing a subtle yet significant shift, and Riot Games is handing players the keys. The company has announced plans to let users control when its powerful Vanguard anti-cheat driver loads, effectively ending its persistent presence at Windows startup. This move introduces a new mode called Vanguard On-Demand, giving gamers greater flexibility over their system security settings without compromising game integrity.

    This change isn’t just about convenience; it’s rooted in cutting-edge operating system features. By leveraging a new element in Windows 11 25H2, the system can now record driver activity even when Vanguard is dormant. This capability allows Vanguard to confirm that no vulnerable drivers have slipped in while the system was idle, streamlining the process and enhancing security monitoring.

    However, this feature isn’t available to everyone automatically. To unlock the On-Demand functionality, PCs must meet a specific set of foundational security requirements. This includes having UEFI Secure Boot, TPM 2.0, Virtualization-Based Security (VBS), Hypervisor-Protected Code Integrity (HVCI), and IOMMU all enabled.

    While these features are standard in many modern prebuilt systems, they often require manual activation or a trip into the BIOS for users to enable them. Riot estimates that while about 35% of players already satisfy this hardware checklist, a significant portion of machines still need configuration. Some gamers will find themselves navigating intricate settings just to access the new functionality.

    The technical complexities behind this system involve deep integration with Microsoft’s Runtime Driver Attestation Report. This mechanism records every driver loaded since boot in an append-only hash stored securely in the TPM. This ensures that Vanguard can verify integrity at launch, closing a potential security gap that necessitated its always-on design.

    The story of Vanguard itself has been a rollercoaster. Riot pushed strong security measures, enforcing requirements like TPM 2.0 and Secure Boot starting in 2020. This focus, while aiming to protect the gaming environment, led to friction with the player base, drawing criticism over mandatory updates and perceived intrusions into system settings.

    The underlying hardware features that enable On-Demand mode—VBS and HVCI—are complex components. Benchmarks have long suggested that enabling these protections can cause a noticeable dip in frame rates, leading many users to disable them for peak performance. Furthermore, activating VBS can sometimes activate Microsoft’s driver blocklist, potentially disabling older peripheral drivers.

    Ultimately, the choice remains with the player: embrace the streamlined security of Vanguard On-Demand, or keep the current setup as-is. Riot is deliberately stepping back, suggesting they are willing to wait for the gaming ecosystem to fully mature before forcing any changes. The power now rests with users who want to balance robust anti-cheat measures with their personal system preferences.