Factlen ExplainerPC GamingPrivacy WinJun 24, 2026, 5:12 PM· 4 min read· #3 of 3 in technology

Riot Games Finally Allows 'On-Demand' Vanguard Anti-Cheat, Ending 24/7 Kernel Tracking

Players with compatible Windows 11 hardware can now opt into 'Vanguard Pre-Check,' allowing the controversial anti-cheat software to run only when games are actively being played.

By Factlen Editorial Team

Privacy & Security Advocates 40%Competitive Players 35%System Architecture Experts 25%
Privacy & Security Advocates
Argue that kernel-level access for video games is an unacceptable security risk and praise the move toward relying on native OS protections.
Competitive Players
Value a cheat-free environment above all else and are cautiously optimistic, provided the on-demand model doesn't lead to a resurgence of hackers.
System Architecture Experts
View this as a necessary evolution in OS design to prevent third-party drivers from destabilizing the entire system.

What's not represented

  • · Cheat Developers

Why this matters

For years, PC gamers have been forced to grant video game companies deep, persistent access to their operating systems just to play popular titles. This update proves that competitive integrity can be maintained without compromising user privacy or system stability.

Key points

  • Riot Games has launched 'Vanguard Pre-Check,' allowing its anti-cheat software to run only when games are active.
  • The feature requires Windows 11, TPM 2.0, and Secure Boot to function.
  • It eliminates the need for Vanguard to monitor a user's PC 24/7 from the moment it boots.
  • The change was made possible by new Microsoft security APIs developed after the 2024 CrowdStrike outage.
  • Older systems without the required hardware will still need to use the always-on version of Vanguard.
Ring-0
Previous Vanguard privilege level
2020
Year Vanguard originally launched
14.9
LoL patch that mandated Vanguard

Riot Games has fundamentally changed how its highly controversial Vanguard anti-cheat software operates, rolling out an update that allows the program to run strictly "on demand." Starting today, players of Valorant and League of Legends are no longer required to let the software run continuously from the moment their computer boots up.[1]

The new feature, dubbed "Vanguard Pre-Check," allows the kernel-level driver to remain dormant until the user actively launches a Riot game. Once the game is closed, the anti-cheat software shuts down with it, returning full autonomy to the user's operating system.[1][4]

To utilize the on-demand feature, players must meet specific hardware and software requirements. The system requires Windows 11 and relies heavily on modern motherboard security features, specifically TPM 2.0 (Trusted Platform Module) and Secure Boot. Players must actively opt into these native Windows protections to bypass Vanguard's traditional always-on requirement.[1][2]

By leaning on Microsoft's native pre-boot security, Riot can verify that the operating system hasn't been compromised by rootkits or stealth cheats before the game starts. This eliminates the need for Vanguard's own driver, known as VGK.sys, to stand guard from the moment the PC is powered on.[2]

How Vanguard Pre-Check eliminates the need for 24/7 kernel monitoring.
How Vanguard Pre-Check eliminates the need for 24/7 kernel monitoring.

The shift marks the end of a long and contentious chapter in PC gaming. When Vanguard originally launched alongside the tactical shooter Valorant in 2020, its design mandated an always-on, kernel-mode driver operating at "Ring-0"—the deepest privilege level of a computer's operating system.[4]

This persistent access sparked intense backlash from privacy advocates and PC enthusiasts. Critics were deeply uncomfortable giving a video game company continuous, unfettered access to their hardware, noting that a vulnerability in Vanguard could theoretically compromise the entire machine.[4]

This persistent access sparked intense backlash from privacy advocates and PC enthusiasts.

The friction intensified in early 2024 when Riot mandated Vanguard for its flagship MOBA, League of Legends. The rollout forced millions of casual players to either accept the intrusive software or abandon a game they had been playing for over a decade. Players frequently complained about the persistent system tray icon and the fact that Vanguard monitored their systems even when they were playing other games or working.[2]

However, the transition to an on-demand model isn't solely a Riot initiative; it is the direct result of a broader architectural shift spearheaded by Microsoft. Following the catastrophic CrowdStrike outage in the summer of 2024—where a faulty kernel-level security update crashed millions of Windows machines globally—Microsoft accelerated efforts to move third-party security software out of the Windows kernel.[3][4]

The new on-demand feature relies heavily on modern motherboard security features like TPM 2.0.
The new on-demand feature relies heavily on modern motherboard security features like TPM 2.0.

Microsoft subsequently developed new Windows capabilities that allow security product developers to validate system integrity from user mode. By providing a secure, native handoff, Microsoft enabled companies like Riot to ensure a machine is cheat-free without needing their own drivers running 24/7.[2][3]

Riot is keeping the always-on version of Vanguard as a fallback. Players on older systems running Windows 10, or those with hardware that lacks TPM 2.0 and Secure Boot capabilities, will still need to run the traditional, persistent version of the anti-cheat software to play.[1][2]

For the millions of players who do meet the criteria, the update is a massive quality-of-life improvement. They no longer have to manually disable Vanguard and reboot their PCs just to run sensitive software, virtualization tools, or other games that occasionally conflicted with Riot's aggressive monitoring.[1][4]

The six-year journey from an always-on kernel driver to an on-demand security model.
The six-year journey from an always-on kernel driver to an on-demand security model.

Industry analysts view Riot's implementation of Vanguard Pre-Check as a new benchmark for the gaming sector. It challenges other major anti-cheat providers, such as BattlEye and Easy Anti-Cheat, to adopt less invasive methods that respect user boundaries while maintaining competitive integrity.[4]

As operating systems become more locked down and secure by default, the era of video games requiring deep, persistent kernel access may finally be drawing to a close. Vanguard Pre-Check proves that developers can keep hackers at bay without treating their players' computers as hostile territory.[3][4]

How we got here

  1. June 2020

    Riot Games launches Vanguard alongside Valorant, requiring a 24/7 kernel-level driver.

  2. May 2024

    Vanguard is controversially integrated into League of Legends with Patch 14.9.

  3. July 2024

    A faulty kernel update from CrowdStrike crashes millions of PCs, accelerating Microsoft's push to move security software out of the kernel.

  4. June 2026

    Riot officially rolls out Vanguard Pre-Check, allowing the software to run on-demand for compatible systems.

Viewpoints in depth

Privacy & Security Advocates

Argue that kernel-level access for video games is an unacceptable security risk.

For years, cybersecurity experts and privacy advocates have warned against the normalization of kernel-level anti-cheat software. They argue that granting a video game company 'Ring-0' access—the same level of privilege required by the operating system itself—creates a massive attack surface. If a malicious actor were to find a vulnerability in Vanguard's driver, they could theoretically take complete control of millions of PCs. This camp views the shift to an on-demand model as a massive victory, proving that user autonomy doesn't have to be sacrificed for competitive gaming.

Competitive Players

Value a cheat-free environment above all else and are cautiously optimistic.

The core demographic of Valorant and League of Legends prioritizes competitive integrity. While many players disliked the intrusive nature of Vanguard, they tolerated it because it was undeniably effective at keeping aimbots and script kiddies out of their matches. This camp is generally supportive of the Pre-Check update, as it removes the annoyance of the 24/7 system tray icon, but they remain watchful. Their primary concern is whether relying on Windows' native security will be as effective at catching custom, hardware-level cheats as Vanguard's proprietary boot driver.

System Architecture Experts

View this as a necessary evolution in OS design to prevent third-party drivers from destabilizing the system.

Operating system architects have long despised the practice of third-party software hooking deeply into the kernel. The 2024 CrowdStrike incident served as a grim vindication of their concerns, demonstrating how a single bug in a kernel driver can cause global IT infrastructure to collapse. This camp sees Riot's adoption of Microsoft's new user-mode security APIs as a critical step forward. By moving validation to the OS level, Microsoft can ensure that a crash in an anti-cheat program only crashes the game, not the entire computer.

What we don't know

  • Whether cheat developers will find new ways to bypass Windows' native Secure Boot mechanisms to inject hacks before Vanguard launches.
  • If other major anti-cheat providers like Easy Anti-Cheat or BattlEye will adopt similar on-demand models in the near future.

Key terms

Kernel-level access (Ring-0)
The deepest level of access to a computer's operating system, allowing software to interact directly with hardware and memory.
TPM 2.0 (Trusted Platform Module)
A hardware chip on modern motherboards that provides cryptographic keys to secure the boot process.
Secure Boot
A security standard that ensures a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM).
Rootkit
A type of malicious software designed to gain unauthorized access to a computer and hide its presence, often loading before the operating system.

Frequently asked

Do I have to use the on-demand version of Vanguard?

No. If your system doesn't support the required Windows 11 security features, Vanguard will continue to operate in its traditional always-on mode.

Will this make it easier for hackers to cheat?

Riot claims the new method is just as secure, as it relies on Windows' native pre-boot security to verify the system hasn't been tampered with before the game launches.

Does this mean Vanguard is completely removed from the kernel?

Vanguard still utilizes a kernel driver when the game is running, but it no longer needs to run continuously from the moment your PC boots up.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Privacy & Security Advocates 40%Competitive Players 35%System Architecture Experts 25%
  1. [1]The VergePrivacy & Security Advocates

    Riot now lets you enable its anti-cheat when you want to

    Read on The Verge
  2. [2]Riot Games Developer BlogSystem Architecture Experts

    Vanguard x LoL Retrospective

    Read on Riot Games Developer Blog
  3. [3]Microsoft Security BlogSystem Architecture Experts

    Windows security and resiliency: Protecting your business

    Read on Microsoft Security Blog
  4. [4]Factlen Editorial TeamPrivacy & Security Advocates

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.