IOMMU (Input Output Memory Management Unit) must be enabled for certain virtualization and security features to work correctly. If it is turned off, Windows may not be able to isolate memory or run virtualization based protections, which can cause configuration errors or prevent features like VBS and HVCI from activating.
- On Intel systems, this feature is called VT-d (Virtualization Technology for Directed I/O).
- On AMD systems, it's simply called IOMMU (or AMD-Vi).
First, Check if IOMMU Is Already Enabled
Before making any changes in BIOS, let's see if IOMMU is already active on your system.
- Press Windows Key + R to open the Run window.
- Type msinfo32 and press Enter.
- In System Summary, note the value shown next to the Processor. This will help you determine whether you're using an Intel or AMD CPU.
- Look for Kernel DMA Protection.
If Kernel DMA Protection Shows "On"
Good news! IOMMU is already enabled and working on your system.
If you're still receiving a VAN: RESTRICTION error, check our VAN: RESTRICTION guide to make sure all other Vanguard requirements are met.
If Kernel DMA Protection Shows "Off"
IOMMU is not currently active on your system.
Proceed to the next section to enable IOMMU in your BIOS.
If Kernel DMA Protection Is Missing
Some systems may not display this field in System Information, even if the hardware supports IOMMU.
If you don't see Kernel DMA Protection listed, continue to the next section and enable IOMMU in your BIOS to ensure the feature is available to Vanguard.
How to Enable IOMMU in BIOS
If you're unable to locate the settings described, your BIOS may be outdated or your device manufacturer may use different naming conventions: Update BIOS Firmware (AMD/Intel) Note that some systems may not expose these settings at all, depending on the hardware and BIOS version available.
⚠️ Important: About editing your BIOS settings
If you’re not familiar with navigating through your BIOS, please reach out to a professional. Incorrectly configuring BIOS settings can cause issues with your computer-including failure to start up.
The BIOS is highly variable depending on the brand and type of computer or motherboard you are using. So we highly recommend that you reach out to your computer or motherboard manufacturer's support resources to assist you.
Before you begin, you'll need to access your computer's BIOS/UEFI settings.
Access your BIOS
Windows 11
- Open Settings
- Go to System > Recovery
- Under Advanced startup, select Restart now
- After your PC restarts, select Troubleshoot > Advanced options > UEFI Firmware Settings
Windows 10
- Open Settings
- Go to Update & Security > Recovery
- Under Advanced startup, select Restart now
- After your PC restarts, select Troubleshoot > Advanced options > UEFI Firmware Settings
Or just restart your PC and press Del, F2, or F10 before Windows loads. (Key varies by brand)
Enable IOMMU
Intel Systems (VT-d)
- Locate VT-d or Control IOMMU Pre-boot Behavior in your BIOS.
- Set the option to Enabled or Enable IOMMU during boot.
- Save your changes and exit BIOS (usually F10).
Where to find it by brand:
- ASUS: Advanced > System Agent (SA) Configuration > Control IOMMU Pre-boot Behavior > Enable IOMMU during boot
- MSI: Overclocking > CPU Features > Control IOMMU Pre-boot Behavior > Enable IOMMU during boot
- Gigabyte: Settings > Miscellaneous > Intel VT-d > Enabled
- ASRock: Advanced > Chipset Configuration > VT-d > Enabled
AMD Systems (IOMMU)
- Locate IOMMU in your BIOS and set it to Enabled.
- If available, also enable DMA Protection and DMAr Support.
- Save your changes and exit BIOS (usually F10).
Where to find it by brand:
- ASUS: Advanced > AMD CBS > IOMMU > Enabled. Then Advanced > AMD CBS > NBIO Common Options > DMA Protection > Enabled, DMAr Support > Enabled
- MSI: Overclocking > Advanced CPU Configuration > AMD CBS > NBIO Common Options > IOMMU > Enabled. Also set DMA Protection and DMAr Support to Enabled if shown.
- Gigabyte: Settings > Miscellaneous > IOMMU > Enabled
- ASRock: Advanced > AMD CBS > NBIO Common Options > IOMMU > Enabled
Note: DMA Protection and DMAr Support may not appear on all boards. If you don't see them, just enabling IOMMU is sufficient.
Note: BIOS layouts and setting names vary between manufacturers and motherboard models. If you're unable to locate these settings, consult your device or motherboard manufacturer's support documentation.
Additional IOMMU Troubleshooting
If you encounter any issues with the steps above, check below for more help.
“A system restart is required to complete initialization?”
This means you've enabled IOMMU in BIOS but haven't fully restarted yet, or the BIOS change didn't apply properly.
- Fully shut down your PC (don't use "Restart" - use Shut down, wait 10 seconds, then power on).
- If it persists, go back into BIOS and confirm IOMMU/VT-d is still set to Enabled (some boards reset on failed boot).
I can’t find VT-d or IOMMU in my BIOS.
The setting name and location varies significantly by motherboard brand and BIOS version. Try these tips:
- Use BIOS search: Some modern BIOSes have a search function (often F9 or Ctrl+F). Search for VT-d, IOMMU, or DMA.
- Check Chipset settings: On Intel, VT-d is sometimes under Chipset or PCH Configuration rather than CPU settings.
- Check for AMD CBS: On AMD, IOMMU can be buried under AMD CBS > NBIO Common Options > IOMMU, which isn't always visible by default.
- Update your BIOS: Older BIOS versions may hide or not expose the IOMMU setting. A BIOS update from your manufacturer may add it.
IOMMU is enabled, but Kernel DMA Protection still shows Off.
This is usually fine. Vanguard checks that IOMMU is enabled in BIOS - it doesn't require Windows to report Kernel DMA Protection as "On." If Vanguard is no longer showing the restriction error, you're good.
Kernel DMA Protection requires additional hardware support (DMA remapping from 2018+ systems) and in some cases a clean Windows install with IOMMU already enabled. These are not Vanguard requirements.
Will enabling IOMMU affect my performance?
No. IOMMU has negligible performance impact on modern systems. It's been enabled by default on most pre-built PCs and laptops for years. You won't notice any difference in gaming performance.
My motherboard doesn’t support IOMMU.
Nearly all motherboards from the last 10 years support IOMMU/VT-d. If your board genuinely doesn't (very old chipsets), it may not meet Vanguard's requirements.
Check your motherboard's spec sheet on the manufacturer's website to confirm IOMMU/VT-d support. If it's not listed, a BIOS update may add it, or you may need to contact your manufacturer.
Getting a “VAN: Incompatible OEM Driver” error?
Some pre-installed OEM drivers are incompatible with DMA protection. Update or uninstall the flagged driver, then restart.
For full details and known affected drivers, see: VAN: Incompatible OEM Driver.
Vanguard says to update motherboard firmware.
Some motherboards have a bug where they report Pre-Boot DMA Protection as active while IOMMU isn't fully initialized. Riot discovered this gap and now requires a BIOS firmware update to fix it.
- Press Windows Key + R, type msinfo32, hit Enter.
- Note your BaseBoard Manufacturer and BaseBoard Product (this is your motherboard model).
- Visit your manufacturer's support/downloads page (links below), search for your exact model, and download the latest BIOS.
- Follow the manufacturer's flashing instructions (usually involves a USB drive and a BIOS utility).
- After updating, go back into BIOS and confirm IOMMU is still Enabled.
Manufacturer BIOS download pages:
- ASUS Download Center
- MSI Support Downloads
- Gigabyte Support
- ASRock Support
- Dell / Alienware Support
- Lenovo Support
- NZXT Support
Tip: Most manufacturers have a BIOS flashback or EZ Flash utility built into the BIOS itself. You typically download the BIOS file, put it on a FAT32-formatted USB drive, then use the built-in utility to flash it. Do NOT turn off your PC during a BIOS update.
See Vanguard Security Update: Closing the Pre-Boot Gap for full details on why this is required.
