Riot Vanguard finally drops its controversial always-on requirement for anti-cheat — new on-demand mode requires a strict Windows 11 security stack

Riot Games Vanguard
(Image credit: Riot Games)

Riot Games has announced that it plans to let players stop its Vanguard anti-cheat from loading at Windows start-up, the company has announced, ending the boot-time behavior the kernel driver has had since 2020. The new mode, Vanguard On-Demand, loads the driver only when a Riot game launches and unloads it on exit, made possible by a Windows 11 25H2 feature that records driver activity even while Vanguard is dormant. It works only on PCs that also have UEFI Secure Boot, TPM 2.0, Virtualization-Based Security (VBS), Hypervisor-Protected Code Integrity (HVCI), and IOMMU switched on. Riot anti-cheat lead Phillip Koskinas said roughly 35% of players already clear that bar, while about 3% are running incompatible hardware.

Riot calls the qualifying checklist Vanguard Pre-Check, and many prebuilt PCs and laptops sold in the past couple of years ship with the features on by default, and Koskinas estimates the share of fully secured machines at 34.33% and rising one to two percentage points a month. Everyone else will need to enable the settings manually, and most are UEFI options that Vanguard can’t change, meaning a trip into BIOS for those who want to do so.

The feature leans on Microsoft's Runtime Driver Attestation Report, built with the company's Xbox OS Security team and new to Windows 11 25H2. It records every driver loaded since boot as a running, append-only hash kept in the TPM, which is the same measured-boot method the Windows Boot Manager already uses for boot-start drivers. Vanguard can then confirm at launch that no vulnerable driver slipped in while it sat idle, closing the gap that forced the always-on design before. Older Windows releases lack that reporting hook, however, so 25H2 is a baseline requirement.

Latest Videos From

Riot Games has spent years pushing the same security stack as a barrier to play, having begun enforcing TPM 2.0 and Secure Boot on Windows 11 in 2020. The company drew backlash when it brought it to League of Legends in 2024, and in December, flagged a pre-boot motherboard flaw across Asus, Gigabyte, MSI, and ASRock boards. Last month, a Vanguard update bricked DMA cheat hardware in a move that was likely tied to stricter IOMMU enforcement.

VBS and HVCI are likely to become sticking points for users who are most likely to want the option to toggle Vanguard’s anti-cheat. Both run parts of the kernel inside a hardware-isolated enclave, and benchmarks have long since shown a small but noticeable degradation to frame rate, which is why many gamers leave them off. Turning VBS on also activates Microsoft's vulnerable driver blocklist, which can disable older peripheral drivers.

Alternatively, payers can leave Vanguard as-is, with Riot saying it’s not “making anyone change anything” and is willing to wait until the ecosystem matures.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Luke James
Contributor

Luke James is a freelance writer and journalist.  Although his background is in legal, he has a personal interest in all things tech, especially hardware and microelectronics, and anything regulatory. 

  • hotaru251
    ...or just don't play any game that uses it.
    Reply
  • Cyber_Akuma
    The toggle needs Windows 11 25H2 plus TPM 2.0, Secure Boot, VBS, HVCI, and IOMMU.
    ... Kernel-level anticheat is already intrusive enough and I will never allow it on my system, this is comically over-the-top to an absurd degree. Might as well agree to let them them have all your passwords and be allowed to to remote into your system whenever they want. This thing is one exploit away from everyone who has a RIOT game installed being turned into a botnet while all their info and credentials are stolen.
    Reply
  • GeorgeLY
    LOL! And there are people stupid enough to install that.
    Reply
  • ClemCa
    Cyber_Akuma said:
    This thing is one exploit away from everyone who has a RIOT game installed being turned into a
    All the features that need to be on are security features. They're not required because they help looking into drivers (they already do that, that's why some drivers don't work with vanguard running), but because they prevent other software from messing with Vanguard pretty much. They also make it harder to mess with software in general really. That's precisely meant to avoid that one exploit that would turn Vanguard into such a tool.

    Vanguard checking the past driver activity on launch is no different from Vanguard doing so permanently from boot before. So it's not more intrusive, it's just as intrusive as before. It was always an intrusive anticheat
    Reply