Skip to main content
ExplainerPC GamingPrivacy Win· 4 min read· in Technology

Riot Games Finally Allows 'On-Demand' Vanguard Anti-Cheat, Ending 24/7 Kernel Tracking

Players with compatible Windows 11 hardware can now opt into 'Vanguard Pre-Check,' allowing the controversial anti-cheat software to run only when games are actively being played.

By Beatriz Santos

Privacy & Security Advocates 40%Competitive Players 35%System Architecture Experts 25%
Privacy & Security Advocates
Argue that kernel-level access for video games is an unacceptable security risk and praise the move toward relying on native OS protections.
Competitive Players
Value a cheat-free environment above all else and are cautiously optimistic, provided the on-demand model doesn't lead to a resurgence of hackers.
System Architecture Experts
View this as a necessary evolution in OS design to prevent third-party drivers from destabilizing the entire system.

Perspectives this story doesn't cover

  • Cheat Developers

Key points

  1. Riot Games has launched 'Vanguard Pre-Check,' allowing its anti-cheat software to run only when games are active.
  2. The feature requires Windows 11, TPM 2.0, and Secure Boot to function.
  3. It eliminates the need for Vanguard to monitor a user's PC 24/7 from the moment it boots.
  4. The change was made possible by new Microsoft security APIs developed after the 2024 CrowdStrike outage.
  5. Older systems without the required hardware will still need to use the always-on version of Vanguard.

Riot Games has fundamentally changed how its highly controversial Vanguard anti-cheat software operates, rolling out an update that allows the program to run strictly "on demand." Starting today, players of Valorant and League of Legends are no longer required to let the software run continuously from the moment their computer boots up.[1]

The new feature, dubbed "Vanguard Pre-Check," allows the kernel-level driver to remain dormant until the user actively launches a Riot game. Once the game is closed, the anti-cheat software shuts down with it, returning full autonomy to the user's operating system.[1][4]

To utilize the on-demand feature, players must meet specific hardware and software requirements. The system requires Windows 11 and relies heavily on modern motherboard security features, specifically TPM 2.0 (Trusted Platform Module) and Secure Boot. Players must actively opt into these native Windows protections to bypass Vanguard's traditional always-on requirement.[1][2]

By leaning on Microsoft's native pre-boot security, Riot can verify that the operating system hasn't been compromised by rootkits or stealth cheats before the game starts. This eliminates the need for Vanguard's own driver, known as VGK.sys, to stand guard from the moment the PC is powered on.[2]

How Vanguard Pre-Check eliminates the need for 24/7 kernel monitoring.

The shift marks the end of a long and contentious chapter in PC gaming. When Vanguard originally launched alongside the tactical shooter Valorant in 2020, its design mandated an always-on, kernel-mode driver operating at "Ring-0"—the deepest privilege level of a computer's operating system.[4]

This persistent access sparked intense backlash from privacy advocates and PC enthusiasts. Critics were deeply uncomfortable giving a video game company continuous, unfettered access to their hardware, noting that a vulnerability in Vanguard could theoretically compromise the entire machine.[4]

This persistent access sparked intense backlash from privacy advocates and PC enthusiasts.

The friction intensified in early 2024 when Riot mandated Vanguard for its flagship MOBA, League of Legends. The rollout forced millions of casual players to either accept the intrusive software or abandon a game they had been playing for over a decade. Players frequently complained about the persistent system tray icon and the fact that Vanguard monitored their systems even when they were playing other games or working.[2]

However, the transition to an on-demand model isn't solely a Riot initiative; it is the direct result of a broader architectural shift spearheaded by Microsoft. Following the catastrophic CrowdStrike outage in the summer of 2024—where a faulty kernel-level security update crashed millions of Windows machines globally—Microsoft accelerated efforts to move third-party security software out of the Windows kernel.[3][4]

The new on-demand feature relies heavily on modern motherboard security features like TPM 2.0.

Microsoft subsequently developed new Windows capabilities that allow security product developers to validate system integrity from user mode. By providing a secure, native handoff, Microsoft enabled companies like Riot to ensure a machine is cheat-free without needing their own drivers running 24/7.[2][3]

Riot is keeping the always-on version of Vanguard as a fallback. Players on older systems running Windows 10, or those with hardware that lacks TPM 2.0 and Secure Boot capabilities, will still need to run the traditional, persistent version of the anti-cheat software to play.[1][2]

For the millions of players who do meet the criteria, the update is a massive quality-of-life improvement. They no longer have to manually disable Vanguard and reboot their PCs just to run sensitive software, virtualization tools, or other games that occasionally conflicted with Riot's aggressive monitoring.[1][4]

The six-year journey from an always-on kernel driver to an on-demand security model.

Industry analysts view Riot's implementation of Vanguard Pre-Check as a new benchmark for the gaming sector. It challenges other major anti-cheat providers, such as BattlEye and Easy Anti-Cheat, to adopt less invasive methods that respect user boundaries while maintaining competitive integrity.[4]

As operating systems become more locked down and secure by default, the era of video games requiring deep, persistent kernel access may finally be drawing to a close. Vanguard Pre-Check proves that developers can keep hackers at bay without treating their players' computers as hostile territory.[3][4]

Key terms

Kernel-level access (Ring-0)
The deepest level of access to a computer's operating system, allowing software to interact directly with hardware and memory.
TPM 2.0 (Trusted Platform Module)
A hardware chip on modern motherboards that provides cryptographic keys to secure the boot process.
Secure Boot
A security standard that ensures a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM).
Rootkit
A type of malicious software designed to gain unauthorized access to a computer and hide its presence, often loading before the operating system.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Privacy & Security Advocates 40%Competitive Players 35%System Architecture Experts 25%
  1. [1]The VergePrivacy & Security Advocates

    Riot now lets you enable its anti-cheat when you want to

    Read on The Verge
  2. [2]Riot Games Developer BlogSystem Architecture Experts

    Vanguard x LoL Retrospective

    Read on Riot Games Developer Blog
  3. [3]Microsoft Security BlogSystem Architecture Experts

    Windows security and resiliency: Protecting your business

    Read on Microsoft Security Blog
  4. [4]Factlen Editorial TeamPrivacy & Security Advocates

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.