VAN RESTRICTION: Vanguard wants a Windows update or a security feature on
Riot VanguardLeague + VALORANTThe message
Error VAN: RESTRICTIONWhat it means
Vanguard won't let the game start until Windows is updated or a specific security feature is switched on. Your account is fine.
What to try first
Read the full message: it names the one requirement you're missing. Fix only that, then restart the PC.
Is it you or Riot? If lots of players are hitting this at once, it's probably the servers. Check League server status before you start reinstalling things.
First, check you're on the right restriction
Riot splits this error into five separate articles, and the only thing that tells them apart is what comes after the word RESTRICTION. Look at the end of your message:
- Nothing after it: you're on the right page. Keep reading.
- RESTRICTION: 1, UEFI Secure Boot verification failure: see VAN: RESTRICTION: 1.
- RESTRICTION: 3, Boot Device Verification Failure (the game is on the wrong drive): see VAN: RESTRICTION: 3.
- RESTRICTION: 4, Secure Boot verification failure: see VAN: RESTRICTION: 4.
- RESTRICTION: 5, Memory Integrity (HVCI/VBS): see VAN: RESTRICTION: 5.
Only one of the steps below is yours
The numbered restrictions each point at one thing. This one doesn't, because it's the catch-all: Vanguard wants either a newer Windows build or one security feature switched on, and the wording of your message says which. Riot's fix is to act on that line and nothing else. So don't work down the list below from the top. Find the step that matches what your message names, do it, restart.
Closed the message already? Riot's security requirements page says the Vanguard tray icon (VGTray, down by the clock) lists whichever requirement still needs attention, with links to the matching fix.
The two Windows build numbers
If the message is about Windows, it asks for one of two builds. Build 19045 or newer is reachable by installing every update Windows offers. Build 26100 or newer is a different story: Riot says only Windows 11 can meet that one, so a Windows 10 PC that gets it has to upgrade to Windows 11 to keep playing. Press Win+R and run winver to see which build you're on.
That floor sits well above the older Vanguard codes about Windows versions. VAN 9004 and VAN 9006 only ask for Windows 10 20H1 or newer.
A TPM that passes VAN 9001 can still fail here
If TPM is the feature your message names, the chip matters. Riot's TPM guide says a plug-in TPM 2.0 module on the motherboard header is enough for VAN 9001, but a restriction specifically wants the firmware TPM built into the CPU (Intel PTT, or fTPM on AMD Ryzen). If you've got a discrete module, switch the BIOS over to the firmware one.
It isn't a ban
Riot files all five restriction articles in the penalties section of its support site (it's right there in the URL), which is enough to worry anyone. Nothing in them describes a penalty on your account. Meet the requirement and the error goes away. A hardware ban has its own code, VAN 152, and reads very differently.
Riot's fix, in Riot's order
These are the requirements a bare VAN: RESTRICTION can name. Do the one your message asks for, then restart.
Install every pending Windows update
Open Settings, then Windows Update, and keep installing and restarting until it says you're up to date. Vanguard's checks lean on security components that ship in those updates, and optional driver updates are worth a look while you're there.
Turn on TPM 2.0
Press Win+R and run
tpm.msc. "The TPM is ready for use" with Specification Version 2.0 means you're fine. Version 1.2 isn't enough, and "Compatible TPM cannot be found" means it's switched off in the BIOS.To switch it on, reach the firmware settings from Windows (Settings, Recovery, Advanced startup, then Troubleshoot, Advanced options, UEFI Firmware Settings) or press Del, F2 or F10 while the PC starts. On Intel boards enable PTT (Platform Trust Technology); on AMD enable fTPM. Save with F10. A plug-in TPM chip covers VAN 9001, but a VAN: RESTRICTION wants the firmware TPM specifically.
Riot's guide: Turn on TPM 2.0
Turn on Secure Boot
Run
msinfo32. You want BIOS Mode: UEFI and Secure Boot State: On. UEFI with Secure Boot off means flipping one switch in the BIOS.If BIOS Mode says Legacy, stop. Your Windows drive has to be converted from MBR to GPT before you switch the BIOS to UEFI, or Windows won't boot at all. Riot's Secure Boot guide covers the conversion and its requirements (64-bit Windows 10 1703 or newer, BitLocker off, no dual boot).
Riot's guide: Turn on Secure Boot
Turn on Memory Integrity (HVCI/VBS)
Run
msinfo32and look at Virtualization-based security near the bottom. Running is good. Enabled but not running means virtualization is off in the BIOS. Not enabled means you haven't switched it on in Windows yet.In Windows Security, open Device security, then Core isolation, and turn on Memory integrity. If the switch is grayed out, enable CPU virtualization in the BIOS first (Intel VT-x, AMD SVM). An incompatible driver can also block the toggle, and Windows names it when that happens.
Riot's guide: Turn on Memory Integrity (HVCI/VBS)
Turn on IOMMU
In
msinfo32, Kernel DMA Protection: On means it's already running. Otherwise enable it in the BIOS: VT-d on Intel, IOMMU or AMD-Vi on AMD. Some older boards only expose it after a BIOS update.Riot's guide: Turn on IOMMU
Other wordings of the same error
VAN RESTRICTIONVAN: RESTRICTION errorVanguard restriction
Related errors
- VAN: RESTRICTION: 1
- VAN: RESTRICTION: 3
- VAN: RESTRICTION: 4
- VAN: RESTRICTION: 5
- VAN 9001
- VAN 9003
- VAN 9004
- VAN 9005
- VAN 152
Source: Riot Games Player Support, Error VAN: RESTRICTION, updated May 29, 2026. Riot's steps are paraphrased here, not copied; checked September 25, 2026.