Vanguard On-Demand Guide 2026
What Vanguard Pre-Check changes, every Windows and firmware requirement, how to verify your PC safely and what to do when the On-Demand button does not appear.
Vanguard On-Demand is an optional mode for sufficiently secured Windows 11 PCs. Instead of loading Vanguard’s driver when Windows starts, the driver starts with a supported Riot title and remains active while you play. To qualify, Riot requires Windows 11 25H2 or newer, UEFI Secure Boot, TPM 2.0, VBS, HVCI and IOMMU. If you do not qualify or do not want to change these settings, you can leave Vanguard in its traditional startup mode.
What Vanguard On-Demand actually changes
Vanguard traditionally loads its driver during system startup. That gives the anti-cheat a continuous trust chain: if a vulnerable driver or pre-boot compromise appears before the game, Vanguard does not have to reconstruct what happened later.
Windows 11 25H2 adds the driver-attestation capability Riot needs to inspect the chain of drivers loaded since boot. On a PC that also passes Vanguard Pre-Check, Riot can delay Vanguard’s own driver until a Riot title starts without giving up the security evidence it needs.
| Area | Traditional mode | On-Demand mode |
|---|---|---|
| Driver start | Starts during Windows boot | Starts when a supported Riot title launches |
| Between sessions | Vanguard remains part of the startup trust chain | Vanguard is not intended to remain active after the Riot title closes |
| Security basis | Vanguard watches continuity from boot | Pre-Check plus Windows driver attestation and hardware security |
| Eligibility | Normal supported Vanguard environment | All Pre-Check requirements must pass |
| Kernel driver removed? | No | No; only its lifecycle changes |
Vanguard Pre-Check requirements
Riot lists the following stack as the baseline for On-Demand. Treat it as an all-items checklist: having TPM 2.0 is not enough if Secure Boot, Memory Integrity or IOMMU is still off.
| Requirement | What Pre-Check needs | Where to verify |
|---|---|---|
| Windows | Windows 11 version 25H2 or newer | winver |
| Boot mode | UEFI, not Legacy/CSM | msinfo32 → BIOS Mode |
| Secure Boot | Enabled and reported as On | msinfo32 → Secure Boot State |
| TPM | TPM specification version 2.0 | tpm.msc |
| VBS and HVCI | Virtualization-Based Security and Memory Integrity active | Windows Security → Device security |
| IOMMU | Firmware IOMMU enabled; commonly Intel VT-d or AMD-Vi/IOMMU | msinfo32 → Kernel DMA Protection |
Check your PC before changing anything
Do the read-only checks first. They tell you what is missing without sending you into firmware menus unnecessarily.
How to enable Vanguard On-Demand safely
The Pre-Check security stack in plain English
Riot’s design is not based on one magic toggle. Secure Boot protects the beginning of the chain, TPM records trusted measurements, VBS/HVCI harden kernel execution, and IOMMU limits direct device access to memory. Windows 11 25H2 then gives Vanguard a way to inspect the driver history created while Vanguard itself was not running.
Common Vanguard On-Demand problems
| Symptom | Likely cause | Safest next step |
|---|---|---|
| No On-Demand button | Old Windows/Vanguard build or an unmet Pre-Check item | Update, restart and open VGTray for the exact missing requirement |
| Secure Boot says Unsupported | System is using Legacy/CSM or firmware keys are not configured | Check disk/boot compatibility and follow the exact PC or motherboard guide |
| TPM cannot be found | Firmware TPM/PTT is disabled or the platform lacks TPM 2.0 | Check for AMD fTPM, Intel PTT or Security Device Support in vendor documentation |
| Memory Integrity will not turn on | An incompatible kernel driver is installed | Use Windows Security’s driver list; update or remove the affected vendor software |
| Kernel DMA Protection is Off | IOMMU/VT-d/AMD-Vi or firmware virtualization is disabled, unsupported or not exposed correctly | Use model-specific firmware documentation; unsupported hardware may not qualify |
| VALORANT fails after setup | Vanguard service, driver or restart state did not initialize correctly | Restart first; then use the dedicated VAN 57 or launch-failure guide for the displayed error |
| Managed work or school PC | Security settings are controlled by policy | Do not bypass policy; ask the device administrator |
Protect the PC before entering BIOS or UEFI
- Back up the BitLocker recovery key. Microsoft documents TPM, boot and UEFI changes as possible BitLocker recovery triggers.
- Record the current firmware values. Photograph only your own current settings so you can restore them accurately.
- Use the exact model page. Laptop, prebuilt and motherboard menus differ even when they use the same CPU.
- Do not clear the TPM. Enabling TPM support is not the same as clearing stored keys. Clearing can affect encrypted data and sign-in credentials.
- Do not switch Legacy to UEFI blindly. The Windows installation and disk layout must be compatible or the system may stop booting.
- Do not update BIOS only because a random guide says so. Update only when the manufacturer recommends the correct package for the exact model.
Performance, privacy and common misconceptions
The practical benefit is control over when Vanguard is active. Do not promise lower input latency, extra FPS or fewer crashes without testing the individual PC. HVCI and virtualization can also expose old, incompatible drivers; that is a security signal to update the driver, not a reason to force the check.
Finish the security check before your next ranked session
Once Vanguard and Windows are stable, choose a VALORANT account that matches your region, rank direction and agent access. Never troubleshoot firmware while an important ranked session is waiting.
Vanguard On-Demand FAQ
What is Vanguard On-Demand?
It is an optional Vanguard mode for secured Windows 11 PCs. Vanguard’s driver starts with a supported Riot title instead of loading during Windows startup, then remains active while the title is running.
What does Vanguard Pre-Check require?
Riot lists Windows 11 25H2 or newer, UEFI Secure Boot, TPM 2.0, Virtualization-Based Security, HVCI or Memory Integrity, and IOMMU.
Is Vanguard On-Demand mandatory?
No. Riot describes it as completely optional. If you prefer not to modify Windows or firmware settings, leave Vanguard in its traditional startup mode.
Does On-Demand remove Vanguard’s kernel driver?
No. The driver still protects the game while a supported Riot title is running. On-Demand changes when the driver loads and stops.
Can Windows 10 use Vanguard On-Demand?
No. Riot states that Pre-Check requires at least Windows 11 version 25H2 because the necessary runtime driver-attestation capability is tied to that Windows version.
Why is my On-Demand option missing?
Update Windows, the Riot client and Vanguard, restart the PC and open VGTray. The Pre-Check workflow should identify whether Windows version, Secure Boot, TPM, Memory Integrity or IOMMU is blocking eligibility.
Will Vanguard On-Demand increase FPS?
Riot does not present the feature as an FPS upgrade. Its main benefit is changing Vanguard’s lifecycle between sessions. Performance results can vary by PC.
Should I clear TPM to pass Pre-Check?
No. Clearing a TPM is not a normal enablement step and can affect BitLocker and stored credentials. Use the PC manufacturer’s instructions to enable TPM support without clearing it.
Official documentation behind this guide
Requirements and behavior were checked against Riot’s On-Demand announcement and support routes. Windows verification and firmware safety were checked against current Microsoft documentation. Firmware labels still vary by manufacturer, so the exact device manual remains the authority for BIOS or UEFI changes.