Local Security Authority protection is off (but it's on)

Anonymous
2023-02-24T07:31:45+00:00

Hello,

The latest of fun W11 bugs has hit me.

Windows Security is telling me Local Security Authority protection is off - but actually it's on.

So I switch it off and on and restart the system but the warning is still there.

I have done this maybe 10 times but the warning is always there.

What is the fix for this?

Thanks

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Sumit 44,306 Reputation points Volunteer Moderator
2023-03-22T00:00:22+00:00

Microsoft has confirmed the issue.

https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#3048msgdesc

After installing "Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2302.21002)", you might receive a security notification or warning stating that "Local Security protection is off. Your device may be vulnerable." and once protections are enabled, your Windows device might persistently prompt that a restart is required. Important: This issue affects only "Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2302.21002)". All other Windows updates released on March 14, 2023 for affected platforms (KB5023706 and KB5023698), do not cause this issue.

Workaround: If you have enabled Local Security Authority (LSA) protection and have restarted your device at least once, you can dismiss warning notifications and ignore any additional notifications prompting for a restart. You can verify that LSA protection is enabled by looking in Event Viewer using the information available here. Important: Currently, we do not recommend any other workaround for this issue.

Next steps: We are working on a resolution and will provide an update as soon as it is available.

Was this answer helpful?

300+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2023-02-24T14:54:41+00:00

Solution 2 worked for me, however I had to search online for the location of the registry path that the post does not mention. Highly advise to backup your registry or create a restore point to be on the safe side before beginning. I tried this on my test machine running Windows 11 Pro, so I don't care if it falls apart.

Went to the registry path "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa"

I added RunAsPPLBoot as DWORD with a value of '2'

I already had RunAsPPL with a value of '2'

Rebooted and no more "This change requires you to restart your device" message.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2023-05-05T08:13:21+00:00

Microsoft now resolves this issue.

"Local Security Authority protection is off." with persistent restart

Resolved: 2023-05-03, 13:27 PT

After installing "Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2302.21002)", you might receive a security notification or warning stating that "Local Security protection is off. Your device may be vulnerable." and once protections are enabled, your Windows device might persistently prompt that a restart is required. Important: This issue affects only "Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2302.21002)". All other Windows updates released on March 14, 2023 for affected platforms (KB5023706 and KB5023698), do not cause this issue.

Resolution: This issue was resolved in an update for Microsoft Defender Antivirus antimalware platform KB5007651 (Version 1.0.2303.27001). If you would like to install the update before it is installed automatically, you will need to check for updates.

Affected platforms:

Client: Windows 11, version 22H2; Windows 11, version 21H2

Server: None

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

197 additional answers

Sort by: Newest
  1. Anonymous
    2023-05-13T16:30:09+00:00

    One way to verify LSA started is by using Event Viewer;

    1. Open Event Viewer and expand 'Windows Logs' and select System
    2. There will many thousands of events listed, so create a filtered view by selecting 'Filter Current Log...' on the right menu pane under Actions - System
    3. A 'Filter Current Log' box should appear and here you want to leave everything as is EXCEPT 'Event sources:' which you want to expand and select (only) Wininit (see screenshot)

    Image

    Once you click OK, you should get a list of events (hopefully all working) confirming whether "12: LSASS.exe was started as a protected process with level: 4", which (at least for this device) is showing for me (see screenshot);

    ![Image](https://learn-attachment.microsoft.com/api/attachments/d73cd51f-6fc9-4af7-be2d-f3caee6dce42?platform=QnA

    I have been following these steps (that I found online) to verify that LSA is actually on …

    Verifying LSA protection

    To discover if LSA was started in protected mode when Windows started, search for the following WinInit event in the System log under Windows Logs:

    • 12: LSASS.exe was started as a protected process with level: 4

     I am confused because I can ONLY see this above-mentioned Wininit event in the Event Viewer after performing a Restart (each and every time after a Restart) to confirm that LSA was started in protected mode BUT if I turn my computer on in the morning after performing a total Shut down the night before (or if I turn it back on after a total Shut down at any other time of the day) I cannot find this Wininit event following the above steps  … ONLY after a Restart. Does this even make any sense? Should I not be seeing this event whether I start my computer up again after a complete Shut down or whether I perform a Restart?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-05-13T11:10:11+00:00

    And what if I do not see that it has started successfully?

    Was this answer helpful?

    0 comments No comments