Windows 10: LSA protection - Running LSASS as protected process in Windows 10 22H2

Discus and support LSA protection - Running LSASS as protected process in Windows 10 22H2 in AntiVirus, Firewalls and System Security to solve the problem; We are running Windows 10 22H2 will soon upgrade to Windows 11 23H2.We would like to enable added LSA protection preferably without UEFI lock on our... Discussion in 'AntiVirus, Firewalls and System Security' started by user_08_15, Mar 12, 2025 at 7:52 AM.

  1. LSA protection - Running LSASS as protected process in Windows 10 22H2


    We are running Windows 10 22H2 will soon upgrade to Windows 11 23H2.We would like to enable added LSA protection preferably without UEFI lock on our machines as outlined in Configure added LSA protection Microsoft Learn. However, the methods to implement it this way only refer to Windows 11 22H2 and later.I ran a test on a Win 10 machine by editing the registry as below. Then rebooted.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa"RunAsPPL"=dword:00000002And surprisingly, after reboot, the System log shows the following WinInit event:12: LSASS.exe was started as a protec

    :)
     
  2. UriSSoo Win User

    Disabling LSA protection

    We have an internal issue causing something not to work when the LSA protection is enabled.

    As we also have "Block credential stealing from the Windows local security authority subsystem (lsass.exe)" ASR rule, and following this recommendation that "having both running at the same time would be redundant" we want to turn off the LSA protection.

    The problem starts with the fact that all our devices support Secure Boot and since years we use UEFI based devices.

    On those machines the task of disabling LSA protection seems like very cumbersome and not straight forward.

    Is there more easy and centralized way to disable LSA protection on a few thousands windows machines?

    Thanks in advance
     
  3. LSA Protection

    What I am seeing within the Core Isolation is the following

    1. Memory Integrity
    2. Memory Access Protection
    3. Vulnerable Driver Blocklist

    Are all of the above parts of the LSA system? If so are all supposed to be toggled on?

    Kenneth
     
    KennethYoung5, Mar 12, 2025 at 7:57 AM
    #3
  4. LSA protection - Running LSASS as protected process in Windows 10 22H2

    LSA Protection

    It appears that Acer is blocking this feature from me as when I type LSASS in start and run as the admin nothing happens.

    I click the file location and I am taken to ACER folder.

    Further to this I checked my Systems Information and notice I have Kernal DMA which is on. Is this playing the same role as the LSA

    Kenneth
     
    KennethYoung5, Mar 12, 2025 at 7:57 AM
    #4
Thema:

LSA protection - Running LSASS as protected process in Windows 10 22H2

Loading...
  1. LSA protection - Running LSASS as protected process in Windows 10 22H2 - Similar Threads - LSA protection Running

  2. LSA protection - Running LSASS as protected process in Windows 10 22H2

    in Windows 10 Gaming
    LSA protection - Running LSASS as protected process in Windows 10 22H2: We are running Windows 10 22H2 will soon upgrade to Windows 11 23H2.We would like to enable added LSA protection preferably without UEFI lock on our machines as outlined in Configure added LSA protection Microsoft Learn. However, the methods to implement it this way only...
  3. LSA protection - Running LSASS as protected process in Windows 10 22H2

    in Windows 10 Software and Apps
    LSA protection - Running LSASS as protected process in Windows 10 22H2: We are running Windows 10 22H2 will soon upgrade to Windows 11 23H2.We would like to enable added LSA protection preferably without UEFI lock on our machines as outlined in Configure added LSA protection Microsoft Learn. However, the methods to implement it this way only...
  4. securityhealthservice.exe disabling LSA protection

    in Windows 10 Gaming
    securityhealthservice.exe disabling LSA protection: Greetings,I am experiencing an issue where securityhealthservice.exe process is trying to disable LSA protection. This action is blocked by an antivirus tool on my PC.I am not sure why this is happening. I have searched online if anyone else was experiencing this issue and I...
  5. securityhealthservice.exe disabling LSA protection

    in Windows 10 Software and Apps
    securityhealthservice.exe disabling LSA protection: Greetings,I am experiencing an issue where securityhealthservice.exe process is trying to disable LSA protection. This action is blocked by an antivirus tool on my PC.I am not sure why this is happening. I have searched online if anyone else was experiencing this issue and I...
  6. LSA Protection

    in Windows 10 Gaming
    LSA Protection: What exactly is LSA and is it a default on the Windows Home Edition?Kenneth https://answers.microsoft.com/en-us/windows/forum/all/lsa-protection/352c6c10-d0d5-4bc9-88d9-2ec510492aef
  7. LSA Protection

    in Windows 10 Software and Apps
    LSA Protection: What exactly is LSA and is it a default on the Windows Home Edition?Kenneth https://answers.microsoft.com/en-us/windows/forum/all/lsa-protection/352c6c10-d0d5-4bc9-88d9-2ec510492aef
  8. Disabling LSA protection

    in Windows 10 Gaming
    Disabling LSA protection: We have an internal issue causing something not to work when the LSA protection is enabled. As we also have "Block credential stealing from the Windows local security authority subsystem lsass.exe" ASR rule, and following this recommendation that "having both running at the...
  9. Disabling LSA protection

    in Windows 10 Software and Apps
    Disabling LSA protection: We have an internal issue causing something not to work when the LSA protection is enabled. As we also have "Block credential stealing from the Windows local security authority subsystem lsass.exe" ASR rule, and following this recommendation that "having both running at the...
  10. Disabling LSA protection

    in AntiVirus, Firewalls and System Security
    Disabling LSA protection: We have an internal issue causing something not to work when the LSA protection is enabled. As we also have "Block credential stealing from the Windows local security authority subsystem lsass.exe" ASR rule, and following this recommendation that "having both running at the...