VALORANT Vanguard On-Demand 2026: Requirements & Setup
VALORANT Technical Guide

Vanguard On-Demand Guide 2026

What Vanguard Pre-Check changes, every Windows and firmware requirement, how to verify your PC safely and what to do when the On-Demand button does not appear.

ALVIRAN EditorialSecurity setup12 min read
StatusOptional mode
Minimum OSWindows 11 25H2
Check toolVanguard Pre-Check
ResultRuns with Riot games
Quick answer

Vanguard On-Demand is an optional mode for sufficiently secured Windows 11 PCs. Instead of loading Vanguard’s driver when Windows starts, the driver starts with a supported Riot title and remains active while you play. To qualify, Riot requires Windows 11 25H2 or newer, UEFI Secure Boot, TPM 2.0, VBS, HVCI and IOMMU. If you do not qualify or do not want to change these settings, you can leave Vanguard in its traditional startup mode.

The change

What Vanguard On-Demand actually changes

Vanguard traditionally loads its driver during system startup. That gives the anti-cheat a continuous trust chain: if a vulnerable driver or pre-boot compromise appears before the game, Vanguard does not have to reconstruct what happened later.

Windows 11 25H2 adds the driver-attestation capability Riot needs to inspect the chain of drivers loaded since boot. On a PC that also passes Vanguard Pre-Check, Riot can delay Vanguard’s own driver until a Riot title starts without giving up the security evidence it needs.

AreaTraditional modeOn-Demand mode
Driver startStarts during Windows bootStarts when a supported Riot title launches
Between sessionsVanguard remains part of the startup trust chainVanguard is not intended to remain active after the Riot title closes
Security basisVanguard watches continuity from bootPre-Check plus Windows driver attestation and hardware security
EligibilityNormal supported Vanguard environmentAll Pre-Check requirements must pass
Kernel driver removed?NoNo; only its lifecycle changes
On-Demand does not uninstall VanguardThe kernel driver still protects the game while a supported Riot title is running. The feature changes when it loads; it does not convert Vanguard into a user-mode anti-cheat.
Eligibility

Vanguard Pre-Check requirements

Riot lists the following stack as the baseline for On-Demand. Treat it as an all-items checklist: having TPM 2.0 is not enough if Secure Boot, Memory Integrity or IOMMU is still off.

RequirementWhat Pre-Check needsWhere to verify
WindowsWindows 11 version 25H2 or newerwinver
Boot modeUEFI, not Legacy/CSMmsinfo32 → BIOS Mode
Secure BootEnabled and reported as Onmsinfo32 → Secure Boot State
TPMTPM specification version 2.0tpm.msc
VBS and HVCIVirtualization-Based Security and Memory Integrity activeWindows Security → Device security
IOMMUFirmware IOMMU enabled; commonly Intel VT-d or AMD-Vi/IOMMUmsinfo32 → Kernel DMA Protection
You may already qualifyRiot reported that roughly 35% of players already met the secured configuration when the feature launched. Newer Windows 11 systems, especially secured-core devices, may need only the Vanguard update and no manual firmware work.
Five-minute audit

Check your PC before changing anything

Do the read-only checks first. They tell you what is missing without sending you into firmware menus unnecessarily.

Confirm Windows 11 25H2 or newerPress Windows + R, enter winver and read the Version line. An older Windows 11 release does not satisfy Riot’s stated minimum.
Open System InformationPress Windows + R, enter msinfo32 and check BIOS Mode, Secure Boot State, Virtualization-Based Security and Kernel DMA Protection.
Verify TPM 2.0Press Windows + R, enter tpm.msc, confirm that the TPM is ready and check that Specification Version reads 2.0.
Check Memory IntegrityOpen Windows Security → Device security → Core isolation details. Memory integrity is Microsoft’s interface for HVCI.
Run Vanguard’s own Pre-CheckOpen the Vanguard tray workflow. VGTray identifies the requirement that is still missing and links to the relevant Riot support page.
Use Riot’s result as the final verdictWindows screens are useful diagnostics, but Vanguard Pre-Check determines whether your actual combination of OS, firmware, security features and drivers qualifies for On-Demand.
Setup path

How to enable Vanguard On-Demand safely

Update Windows and the Riot clientInstall the current supported Windows 11 release and pending Riot/Vanguard updates. Restart before judging the Pre-Check result.
Open Vanguard Pre-CheckUse the Vanguard system-tray application. If every requirement passes, Riot says the option to switch to On-Demand becomes available.
Resolve Windows-side items firstTurn on Memory Integrity through Windows Security when supported. Update any incompatible driver that Windows identifies instead of forcing the setting through registry edits.
Handle firmware items with vendor instructionsIf UEFI, Secure Boot, TPM or IOMMU is missing, use documentation for the exact laptop, prebuilt PC or motherboard model. Menu names and safe conversion steps differ.
Restart and rerun Pre-CheckFirmware and virtualization changes normally require a full restart. Confirm the new state in Windows, then let Vanguard validate it again.
Enable the On-Demand optionUse the option shown by Vanguard after a successful check. Launch VALORANT once, close it normally and verify that the Vanguard tray behavior matches the selected mode.
Do not copy random BIOS valuesDo not flash a BIOS, clear a TPM, convert a system disk or disable Legacy/CSM from a generic video. A wrong firmware change can stop Windows from booting. Use the exact manufacturer’s documentation and keep your recovery information available.
Why each item matters

The Pre-Check security stack in plain English

Windows 11 25H2Driver historyRiot ties the minimum version to Windows’ runtime driver-attestation capability.
Secure BootTrusted startupAllows only trusted, signed boot components and helps block bootkits before Windows loads.
TPM 2.0Hardware trustThe security processor stores measurements and supports the attestation chain used after boot.
VBSIsolated securityUses hardware virtualization to isolate sensitive Windows security work from the normal kernel.
HVCIMemory IntegrityChecks kernel-mode code before it can execute and blocks many vulnerable or unsigned drivers.
IOMMUDMA boundariesControls how PCIe devices reach memory; Windows commonly exposes it through Kernel DMA Protection.

Riot’s design is not based on one magic toggle. Secure Boot protects the beginning of the chain, TPM records trusted measurements, VBS/HVCI harden kernel execution, and IOMMU limits direct device access to memory. Windows 11 25H2 then gives Vanguard a way to inspect the driver history created while Vanguard itself was not running.

TPM nuanceRiot says either a discrete TPM or firmware TPM can satisfy ordinary Pre-Check. A separate Vanguard Restriction can impose stricter requirements. If your account shows a restriction message, use the dedicated VAN:Restriction guide instead of treating it as a normal On-Demand setup.
When Pre-Check fails

Common Vanguard On-Demand problems

SymptomLikely causeSafest next step
No On-Demand buttonOld Windows/Vanguard build or an unmet Pre-Check itemUpdate, restart and open VGTray for the exact missing requirement
Secure Boot says UnsupportedSystem is using Legacy/CSM or firmware keys are not configuredCheck disk/boot compatibility and follow the exact PC or motherboard guide
TPM cannot be foundFirmware TPM/PTT is disabled or the platform lacks TPM 2.0Check for AMD fTPM, Intel PTT or Security Device Support in vendor documentation
Memory Integrity will not turn onAn incompatible kernel driver is installedUse Windows Security’s driver list; update or remove the affected vendor software
Kernel DMA Protection is OffIOMMU/VT-d/AMD-Vi or firmware virtualization is disabled, unsupported or not exposed correctlyUse model-specific firmware documentation; unsupported hardware may not qualify
VALORANT fails after setupVanguard service, driver or restart state did not initialize correctlyRestart first; then use the dedicated VAN 57 or launch-failure guide for the displayed error
Managed work or school PCSecurity settings are controlled by policyDo not bypass policy; ask the device administrator
Failing Pre-Check is not a punishmentRiot describes the feature as optional. A PC that does not qualify can keep using the traditional Vanguard startup model, assuming the device otherwise meets the current requirements for the Riot title.
Before firmware changes

Protect the PC before entering BIOS or UEFI

  • Back up the BitLocker recovery key. Microsoft documents TPM, boot and UEFI changes as possible BitLocker recovery triggers.
  • Record the current firmware values. Photograph only your own current settings so you can restore them accurately.
  • Use the exact model page. Laptop, prebuilt and motherboard menus differ even when they use the same CPU.
  • Do not clear the TPM. Enabling TPM support is not the same as clearing stored keys. Clearing can affect encrypted data and sign-in credentials.
  • Do not switch Legacy to UEFI blindly. The Windows installation and disk layout must be compatible or the system may stop booting.
  • Do not update BIOS only because a random guide says so. Update only when the manufacturer recommends the correct package for the exact model.
Recovery first, optimization secondOn-Demand is optional. If a firmware change is unclear, stop and keep traditional Vanguard startup rather than risking an unbootable or encrypted system.
What to expect

Performance, privacy and common misconceptions

TrueLess startup presenceOn qualifying PCs, Vanguard no longer needs to load its driver with Windows.
Not promisedA large FPS boostRiot presents this as a security and lifecycle change, not a guaranteed performance upgrade.
FalseNo kernel driverThe driver still runs while the protected Riot title is active.
TrueOptional choiceYou can leave Vanguard in its traditional startup configuration.
FalseAny Windows 11 PC worksVersion 25H2 and the complete security stack are required.
TrueHardware can block eligibilityA device without the required firmware security capabilities may be unable to pass.

The practical benefit is control over when Vanguard is active. Do not promise lower input latency, extra FPS or fewer crashes without testing the individual PC. HVCI and virtualization can also expose old, incompatible drivers; that is a security signal to update the driver, not a reason to force the check.

ALVIRAN Marketplace

Finish the security check before your next ranked session

Once Vanguard and Windows are stable, choose a VALORANT account that matches your region, rank direction and agent access. Never troubleshoot firmware while an important ranked session is waiting.

FAQ

Vanguard On-Demand FAQ

What is Vanguard On-Demand?

It is an optional Vanguard mode for secured Windows 11 PCs. Vanguard’s driver starts with a supported Riot title instead of loading during Windows startup, then remains active while the title is running.

What does Vanguard Pre-Check require?

Riot lists Windows 11 25H2 or newer, UEFI Secure Boot, TPM 2.0, Virtualization-Based Security, HVCI or Memory Integrity, and IOMMU.

Is Vanguard On-Demand mandatory?

No. Riot describes it as completely optional. If you prefer not to modify Windows or firmware settings, leave Vanguard in its traditional startup mode.

Does On-Demand remove Vanguard’s kernel driver?

No. The driver still protects the game while a supported Riot title is running. On-Demand changes when the driver loads and stops.

Can Windows 10 use Vanguard On-Demand?

No. Riot states that Pre-Check requires at least Windows 11 version 25H2 because the necessary runtime driver-attestation capability is tied to that Windows version.

Why is my On-Demand option missing?

Update Windows, the Riot client and Vanguard, restart the PC and open VGTray. The Pre-Check workflow should identify whether Windows version, Secure Boot, TPM, Memory Integrity or IOMMU is blocking eligibility.

Will Vanguard On-Demand increase FPS?

Riot does not present the feature as an FPS upgrade. Its main benefit is changing Vanguard’s lifecycle between sessions. Performance results can vary by PC.

Should I clear TPM to pass Pre-Check?

No. Clearing a TPM is not a normal enablement step and can affect BitLocker and stored credentials. Use the PC manufacturer’s instructions to enable TPM support without clearing it.

Sources checked

Official documentation behind this guide

Requirements and behavior were checked against Riot’s On-Demand announcement and support routes. Windows verification and firmware safety were checked against current Microsoft documentation. Firmware labels still vary by manufacturer, so the exact device manual remains the authority for BIOS or UEFI changes.