Skip to content
TroubleGrid

"A driver cannot load on this device" after a Windows update: which block hit you

Last verified October 2026Tested against Windows 11 24H2, 25H2, 26H1 and 26H2, Windows 11 26H2 (general availability 29 September 2026) — consolidates the kernel trust change, Windows Server 2025, Windows 10 (vulnerable driver blocklist, and the April 2026 blocklist update), April 2026 Windows updates (KB5083769) — cross-signed trust evaluation begins; psmounterex.sys added to the blocklist, Vulnerable driver blocklist: on by default since the Windows 11 2022 updateWell documented

Open Event Viewer and go to Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational. Event 3077 means a driver was blocked; Event 3076 means it was only audited and still loaded. If you see 3077, the cause is almost certainly Microsoft's vulnerable driver blocklist or Kernel-mode Hardware-enforced Stack Protection — not April 2026's cross-signed trust removal, which by Microsoft's own rule cannot activate while the untrusted driver is still loading. Each has a different fix, and uninstalling the update is not one Microsoft recommends.

Three separate Windows mechanisms can stop a third-party kernel driver from loading, and all of them land in the same event log with the same two event IDs. That is why the advice online contradicts itself: pages written about one mechanism get applied to another, and the fix for one is useless against the others. This page sorts out which block you actually have before you change any security setting.

Symptoms

  • A device that worked before a Windows update is no longer detected — printer, capture card, network adapter, RGB or fan controller, sensor tool
  • An application that installs its own kernel driver fails to start, or starts and reports that its driver could not be loaded
  • A Windows Security dialog appears saying "A driver cannot load on this device"
  • Backup software fails to mount an image as a virtual drive, or a VSS snapshot times out during creation
  • Event ID 3077 (or 3076) appears under Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational
  • A game using kernel anti-cheat reports "Failed to initialize BattlEye Service: Driver Load Error (1275)"
  • The device or app broke days or weeks after the Windows update that caused it, so the two never looked connected

Why this happens

Microsoft's vulnerable driver blocklist blocked that specific driver

This blocklist names individual drivers known to carry exploitable vulnerabilities. It has been on by default for every device since the Windows 11 2022 update, and it is enforced regardless whenever memory integrity (HVCI), Smart App Control or S mode is active. Microsoft refreshes it quarterly and also ships updates to it inside the monthly Windows updates — which is why a machine can break in a month when nothing about the app changed. In April 2026 the addition of psmounterex.sys broke Macrium Reflect's legacy versions, Acronis Cyber Protect Cloud, UrBackup Server and NinjaOne Backup. A driver already loaded keeps working until the next reboot, which delays the symptom further.

Find out which driver Windows actually blocked · Update the application or driver to a version Windows still trusts · Last resort: turn off the vulnerable driver blocklist

Kernel-mode Hardware-enforced Stack Protection is on, and the driver is on its incompatibility list

This is a separate feature with its own separate blocklist, and unlike the vulnerable driver blocklist it is off by default — somebody turned it on, or accepted a Windows prompt to. It needs Intel CET or AMD Shadow Stacks hardware and VBS plus HVCI. Drivers that hijack return addresses or use obfuscation engines are incompatible, and with the feature on they are simply not allowed to load. Kernel anti-cheat is the common casualty: BattlEye states plainly that enabling the feature stops its driver loading and that many kernel-level anti-cheats are not yet compatible. If your hardware cannot support CET or Shadow Stacks, or VBS and HVCI are off, this is not your cause.

Find out which driver Windows actually blocked · Update the application or driver to a version Windows still trusts · Turn off Kernel-mode Hardware-enforced Stack Protection — only if that is the cause

The April 2026 cross-signed trust removal — which usually audits rather than blocks

From the April 2026 updates, drivers signed under the deprecated cross-signed root program lost default kernel trust; only WHCP-certified drivers and an allow list of widely used legacy drivers remain trusted. Windows 11 version 26H2 consolidates this change. But it rolls out per device in evaluation mode first, and Microsoft's own rule is the important part: enforcement needs a clean run of accumulated uptime and reboots with no policy violations, and if a driver that would be blocked loads during that window the uptime and boot session counters are reset to zero. A cross-signed driver you actually use therefore keeps resetting the clock, so this mechanism tends to log 3076 indefinitely rather than ever reaching 3077 for that driver. That makes it the least likely explanation for a device that genuinely stopped working.

Read the event ID to tell which block you have — and rule the cross-signed policy in or out · Update the application or driver to a version Windows still trusts

Fixes

Find out which driver Windows actually blocked

about 5 min

Windows names the driver in the Code Integrity log but not in the dialog, so this is the one step that turns a vague breakage into a specific file name you can act on.

Applies to: Windows 10, Windows 11 24H2, 25H2, 26H1 and 26H2, Windows Server 2025

  1. Right-click Start and open Event Viewer.
  2. Expand Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational.
  3. Choose Filter Current Log, enter 3076,3077 in the event ID box, and press OK.
  4. Open the newest entry and read the driver file name in the message. That file name is what you give the vendor, or search for on the manufacturer's download page.
  5. If you prefer the command line, run Windows PowerShell as administrator and list the same events. Reading this log requires administrator rights.
    Get-WinEvent -LogName Microsoft-Windows-CodeIntegrity/Operational |
      Where-Object { $_.Id -eq 3076 -or $_.Id -eq 3077 } |
      Select-Object -First 20 TimeCreated, Id, Message |
      Format-List
  6. Note the timestamps. A block that began at a reboot days after a Windows update is the normal pattern here, not a coincidence.

Confirmed by the vendor.

Source: Microsoft, Super User

Read the event ID to tell which block you have — and rule the cross-signed policy in or out

about 5 min

3076 and 3077 mean different things, and the difference decides whether anything is actually being blocked and which of the three mechanisms you are fighting.

Applies to: Windows 11 24H2, 25H2, 26H1 and 26H2, Windows 10, Windows Server 2025

  1. Event 3077 means the driver was blocked in enforcement. Something is genuinely not loading, and your cause is the vulnerable driver blocklist, Kernel-mode Hardware-enforced Stack Protection, or an App Control policy set by your organisation.
  2. Event 3076 means the driver was only audited: it would have been blocked, but it was allowed to load. If your only events are 3076, the cross-signed trust policy has not blocked anything on this machine and is not what broke your device — keep looking.
  3. Check whether Kernel-mode Hardware-enforced Stack Protection is on, at Windows Security > Device security > Core isolation details. If it is Off, it is not your cause. It is off by default, so an On here means it was deliberately enabled. If the toggle is not listed at all, one of its prerequisites is unmet — Microsoft requires Intel CET or AMD Shadow Stacks hardware, a recent Windows Security app, and VBS plus HVCI enabled — and the feature cannot be what blocked your driver.
  4. If that toggle is On and the blocked file belongs to a game's anti-cheat, you have the stack-protection case — BattlEye reports exactly this failure as "Driver Load Error (1275)".
  5. Otherwise check whether memory integrity is on in the same screen. The vulnerable driver blocklist is enforced whenever memory integrity, Smart App Control or S mode is active, and it is on by default even when they are not.
  6. Do not change any of these toggles yet. Identify the mechanism first — the remedies are different and two of them cost you real protection.

Confirmed by the vendor.

Source: Microsoft, Microsoft, Microsoft, BattlEye

Update the application or driver to a version Windows still trusts

about 20 min

This is the only remedy that fixes the problem without giving up a protection, and it is what Microsoft recommends for all three mechanisms.

Applies to: Windows 10, Windows 11 24H2, 25H2, 26H1 and 26H2, Windows Server 2025

  1. Check Windows Update, including optional driver updates under Settings > Windows Update > Advanced options > Optional updates.
  2. Go to the hardware or software vendor's own download page and look for a build released after April 2026, or one that explicitly mentions WHCP certification, memory integrity or Windows 11 compatibility.
  3. Where a vendor has shipped a replacement, take it rather than re-enabling the old driver. Macrium Reflect X was unaffected by the April 2026 block that broke the legacy Reflect versions, for example.
  4. If the vendor has nothing yet, contact them with the exact driver file name from the Code Integrity log and the event ID. That file name is what lets them identify the build.
  5. Reboot after installing. A driver that is already loaded is not stopped until the machine restarts, so the reverse is also true — the new one may not take effect until you do.

Confirmed by the vendor.

Source: Microsoft, Microsoft, BleepingComputer

Turn off Kernel-mode Hardware-enforced Stack Protection — only if that is the cause

Check before applyingabout 10 min

This is the vendor-documented workaround for kernel anti-cheat, and it is narrower than it looks: the feature is off by default, so turning it off returns you to the Windows default rather than below it.

Applies to: Windows 11 on Intel CET or AMD Zen 3 and newer hardware with VBS and HVCI enabled

Before you do this

This removes a kernel exploit mitigation against return-oriented programming attacks, and Microsoft states that disabling it downgrades the security of your device. Turn it off only when you have confirmed it is the cause, and turn it back on once the vendor ships a compatible driver.

  1. Confirm first that this is your cause, using the previous fix. If the toggle is already Off, this will not help you.
  2. Open Windows Security and go to Device security > Core isolation details.
  3. Switch Kernel-mode Hardware-enforced Stack Protection to Off.
  4. Restart the PC, then launch the affected game or application again.
  5. Leave memory integrity itself On. It is a different setting on the same screen and it is not what blocked your driver here, so turning it off as well would give up a separate kernel protection for nothing.
  6. Re-check after the anti-cheat or driver vendor ships an update, and turn the feature back on when it does. BattlEye describes the incompatibility as not resolved yet rather than permanent.

Confirmed by the vendor.

Source: Microsoft, BattlEye, Microsoft

Last resort: turn off the vulnerable driver blocklist

Advancedabout 10 min

Included because people reach for it and should understand what it costs; it is not Microsoft's recommendation and it re-exposes the machine to the exact vulnerability the block was added for.

Applies to: Windows 10, Windows 11 24H2, 25H2, 26H1 and 26H2

Before you do this

This leaves the machine able to load kernel drivers with known, exploitable privilege-escalation vulnerabilities, which is what the blocklist exists to prevent. Microsoft does not recommend it and recommends updating the affected application instead. It also has no effect while memory integrity, Smart App Control or S mode is on.

  1. Exhaust the vendor-update route first. Microsoft's guidance for the April 2026 backup breakage was explicitly to install the latest application versions, not to remove the protection.
  2. Understand what you are turning off: a list of drivers with known privilege-escalation vulnerabilities. The block that broke the backup tools existed to address CVE-2023-43896.
  3. Open Windows Security > Device security > Core isolation details and switch Microsoft vulnerable driver blocklist to Off, then restart.
  4. Note that this does nothing if memory integrity, Smart App Control or S mode is active, because the blocklist is enforced under those regardless of this toggle.
  5. Treat it as temporary. Re-enable it as soon as the vendor ships a driver that loads, and check back rather than leaving it off indefinitely.

Reported to work by 2 users; not confirmed by the vendor.

Source: Microsoft, BleepingComputer

Known issues

  • Microsoft's own two pages disagree on how long the cross-signed evaluation period lasts. The consumer Windows Driver Policy page says the device must accumulate 250 hours of active use; the 26H2 IT-pro page says Windows audits driver compatibility for at least 100 hours and three restarts. Both agree on at least three reboots and on no policy violations, so the practical rule — a driver that would be blocked resets the clock — is unaffected.

    Affects Windows 11 24H2, 25H2, 26H1 and 26H2, Windows Server 2025 · Status: open

  • The April 2026 security updates (KB5083769) added psmounterex.sys to the vulnerable driver blocklist to address CVE-2023-43896, breaking Macrium Reflect legacy versions, Acronis Cyber Protect Cloud, UrBackup Server and NinjaOne Backup. Microsoft confirmed it and said not to uninstall or pause the update; the remedy is a newer application version. Macrium Reflect X was not affected.

    Affects Windows 10, Windows 11, Windows Server, April 2026 security updates (KB5083769) · Status: workaround only

  • BattlEye states that many kernel-level anti-cheats, its own included, are not yet compatible with Hardware-enforced Stack Protection, and that enabling the feature stops its driver loading. Its documented workaround remains turning the feature off rather than a compatible driver.

    Affects Windows 11 with Kernel-mode Hardware-enforced Stack Protection enabled · Status: workaround only

  • Microsoft documents no per-driver or per-application exception for Kernel-mode Hardware-enforced Stack Protection. The controls in Windows Security are all-or-nothing, and Microsoft does not recommend deleting drivers to restore the setting either.

    Affects Windows 11, Windows Server 2025 · Status: open

If none of this worked

If the Code Integrity Operational log has no 3076 or 3077 events at all, none of this is your problem and you should stop changing security settings. A device that stopped working right at a Windows update — rather than days later — is more often a driver that was replaced by a newer one, or a power-management setting that was reset. If your symptom is specifically USB audio with no sound or a Code 10 error, that is a separate September 2026 regression with its own page. If a game or launcher is being blocked but no kernel driver is involved, Smart App Control is the more likely culprit. If lighting and fan control specifically stopped working, the inpoutx64 article covers that driver's three different failure routes in detail. And if the blocked driver belongs to software your employer installed, the block may come from an App Control policy your organisation set rather than from any of the three Windows defaults here.

Common questions

Should I just uninstall the Windows update?
No. On the April 2026 blocklist breakage Microsoft's position was explicit: "We do not recommend uninstalling or pausing this update. Customers with an impacted driver should install the latest application versions." Removing the update also removes security fixes, and the blocklist is refreshed through later monthly updates anyway, so the block usually returns.
Will the cross-signed driver policy block the old driver I use every day?
By Microsoft's documented rule, not while you keep using it. Enforcement only activates after a clean evaluation run with no policy violations, and if a driver that would be blocked loads during that window the uptime and boot session counters are reset to zero. A cross-signed driver in daily use therefore keeps resetting the clock and shows up as audit event 3076 rather than a block. That is also why a device that really did stop working is usually a different mechanism.
Why did my device break weeks after the update rather than immediately?
Two reasons, both normal. A driver that is already loaded is not stopped when a new policy activates — it keeps working until the next reboot. And blocklist updates arrive quarterly as well as inside monthly Windows updates, so the block that affects you may have shipped well after the update you remember installing.
Can I allow just this one driver and leave everything else protected?
For Kernel-mode Hardware-enforced Stack Protection, Microsoft documents no per-driver or per-application exception — the toggle is all-or-nothing. Advice telling you to add a per-app exclusion under Exploit protection is describing the separate user-mode stack protection setting, which does not govern whether a kernel driver loads.
Does enabling test-signing mode or disabling driver signature enforcement fix this?
It is not among Microsoft's documented remedies for any of the three mechanisms, and it lowers the machine's security broadly rather than addressing the specific block. If anti-cheat is involved it also backfires: BattlEye separately documents that Windows Test-Signing Mode is not supported, so you would trade one failure for another.
How do I know whether it is my organisation's policy rather than Windows?
A managed device can carry an App Control for Business policy that blocks drivers independently of the three Windows defaults. If the machine is domain-joined or enrolled in Intune and the blocked driver belongs to software you installed yourself, ask whoever manages it before changing Windows Security settings — the toggles may be enforced centrally and revert.

Did this fix work?

If a step is wrong, outdated, or did not help, telling us is the fastest way to get it corrected. Reports are reviewed before new articles.

Report a problem with this page

Related problems

Sources

  • Microsoft · Support page · checked Oct 7, 2026

    • The Windows Driver Policy is a policy in the Windows kernel that restricts which kernel-mode drivers can load, enforced through kernel Code Integrity.
    • As of April 2026, drivers previously trusted under the deprecated cross-signed root program are no longer trusted by default.
    • Event ID 3076 records a driver that was audited in evaluation mode; Event ID 3077 records a driver that was blocked in enforcement mode.
    • These events are written to Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational.
    • Before enforcement activates, the device must accumulate 250 hours of active use and at least 3 reboots (2 on Windows Server), with no policy violations.
    • If a driver that would be blocked is loaded during the evaluation period, the uptime and boot session counters are reset to zero.
    • Symptoms include a hardware device not functioning correctly, a peripheral or component not being recognised, or an application that depends on a kernel driver failing to start.
    • Microsoft tells affected users to check Windows Update for an updated driver, visit the manufacturer's website, and contact the hardware or software vendor.
  • Microsoft · Documentation · checked Oct 7, 2026

    • Since the Windows 11 2022 update the vulnerable driver blocklist is enabled by default on all devices and can be turned on or off in the Windows Security app.
    • The blocklist is also enforced whenever memory integrity (HVCI), Smart App Control or S mode is active.
    • The blocklist is updated quarterly, and blocklist updates are also delivered through the monthly Windows updates.
    • Blocking drivers can cause devices or software to malfunction, and in rare cases lead to a blue screen.
    • A driver already running when a new policy is activated is not stopped until the computer is rebooted.
    • Microsoft holds back some blocks to avoid breaking existing functionality while partners ship patched driver versions.
  • Microsoft · Documentation · checked Oct 7, 2026

    • Kernel-mode Hardware-enforced Stack Protection is off by default and must be turned on by the user.
    • It requires Intel CET or AMD Shadow Stacks hardware (11th Gen Intel Core Mobile or AMD Zen 3 and newer) and requires VBS and HVCI to be enabled.
    • Windows maintains a known-incompatible driver blocklist for kernel-mode hardware-enforced stack protection, and when the feature is on a listed driver is not allowed to load.
    • When an incompatible driver attempts to load with the feature enabled, a prompt appears saying "A driver cannot load on this device".
    • If the system already has a driver installed that is on the blocklist, the feature fails to enable.
    • The feature is turned on at Windows Security > Device security > Core isolation details > Kernel-mode Hardware-enforced Stack Protection.
    • Disabling the security feature downgrades the security of the device.
  • Microsoft · Support page · checked Oct 7, 2026

    • Turning on Kernel-mode Hardware-enforced Stack Protection blocks incompatible drivers from loading, so Windows turns the setting off to allow those drivers to load.
    • Microsoft's documented remedy is an updated and compatible driver from Windows Update or the manufacturer, and Microsoft does not recommend deleting drivers to restore the setting.
    • The page documents no per-driver or per-application exception for this feature.
  • Microsoft · Documentation · checked Oct 7, 2026

    • Default trust for cross-signed drivers is removed; what remains allowed are drivers from the Windows Hardware Compatibility Program and an allow list of trusted legacy drivers.
    • Windows audits driver compatibility for at least 100 hours and three restarts before enabling enforcement.
    • Windows 11 version 26H2 is delivered as an enablement package to eligible devices running versions 25H2 and 24H2 and shares their servicing branch.
  • BattlEye FAQOfficial

    BattlEye · Support page · checked Oct 7, 2026

    • BattlEye states that if Windows 11 users enable Hardware-enforced Stack Protection it will cause the BattlEye driver to be unable to load.
    • BattlEye states that many kernel-level anti-cheats, including its own, are not compatible with this feature yet.
    • BattlEye's documented workaround is to turn off Kernel-mode Hardware-enforced Stack Protection under Core isolation.
    • BattlEye separately documents that Windows Test-Signing Mode is not supported.
  • BleepingComputer · News · checked Oct 7, 2026

    • The April 2026 security updates (KB5083769) added psmounterex.sys to the vulnerable driver blocklist, addressing CVE-2023-43896.
    • Macrium Reflect legacy versions, Acronis Cyber Protect Cloud, UrBackup Server and NinjaOne Backup were affected; Macrium Reflect X was not.
    • Affected users saw Code Integrity Event ID 3077, failures mounting backup images, and VSS snapshot timeouts.
    • Microsoft stated: "We do not recommend uninstalling or pausing this update. Customers with an impacted driver should install the latest application versions."
  • Super User · Forum · checked Oct 7, 2026

    • Users encountering a blocked-driver prompt report that Windows does not tell them which driver was blocked, and ask how to identify it.