if you have a guest that uses IBRS/IBPB CPU features (e.g., patched Windows, RHEL, SLES) AND a CPU which got support for it via a microcode/BIOS update (on all nodes where you want to potentially run this guest), you can pass through the support to the guest kernel so that it can use the feature.