The Local Security Authority protection is off - Windows 11 Home

Anonymous
2023-03-17T06:10:20+00:00

A yellow triangle appeared on the Windows Security iron yesterday. It says that Local Security Authority protection is off. Your device may be vulnerable.

I can press Go to settings or Dismiss but when I click go to settings, a notification saying "the page You want to access doesn't contain required functions and is unavailable". 

There is also no option to turn the protection on in the Device Security panel (there is only "dismiss" option).

When I was looking at it yesterday, there was also a notification that "The tpm module is unavailable" but today it doesn't show. I checked the device manager and uefi and both say that the tpm is enabled.

I've found an advice to turn on SMV in UEFI (in the CPU settings) to solve the problem but I don't want to change anything in BIOS without consultation as I'm no expert. I've also found a reply from a truste source that this whole problem is a Microsoft bug and it's better to just wait till they fix it.

What should I do?

Screenshots are in Polish, I hope they can be useful somehow. The first one shows the notification about a page being not available and the second shows the Device security panel (the notification from the first screenshot displays when I close the device security page or when I click on "go to settings" below the information that the protection is turned off). There is also an information (second screenshot) that "standard device security is not supported".

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-07-06T07:36:56+00:00

Microsoft have just posted that they have resolved the "Local Security Authority protection is off" issue in an update. Has anyone tried to apply it from Windows Update?

Resolution: This issue was resolved in an update for Windows Security platform antimalware platform KB5007651 (Version 1.0.2306.10002). If you would like to install the update before it is installed automatically, you will need to check for updates.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

174 additional answers

Sort by: Newest
  1. Anonymous
    2023-05-06T17:04:45+00:00

    I got down to LSA but there is no RunAsPPL value in the right pane

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-05-06T09:00:21+00:00

    Ci sono due impostazioni da effettuare in quella chiave, non solo questa..... e il valore dei dati per entrambi deve essere impostato su 2, non su 1.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

    Assicurati di avere RunAsPPL e RunAsPPLBoot.

    In caso contrario, creare voci DWORD per RunAsPPL e RunAsPPLBoot.

    Il valore per entrambe le voci deve essere 2.

    so I solved the problem

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-05-05T20:02:34+00:00

    Hi Grooner. That is interesting. What VS and Build are you using? I'm just curious, as 10 will allow for TPM 1.2, but 11 requires TPM 2.0. It could also have something to do with the MotherBoard Manufacturer and Driver, as the fTPM is based on the MotherBoard. You may know that, I'm just brainstorming and throwing it out there.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-05-05T13:55:12+00:00

    I noticed this warning on Windows Security and also the Device Security page was saying the TPM wasnt found - when fTPM has been working for a while now and it shows up OK in other tools. I had core isolation (VBS) off.

    After enabling core isolation I got the error about ene.sys on next boot. I'm not sure what had added that driver but I deleted the ENE folder, renamed the driver, and removed referring registry keys, to fix this.

    Having VBS enabled does stop Gigabyte SIV utility from displaying some CPU info as it causes cpudump.exe to error. There are also now warnings about Credential Guard as that seems to be enabled but is only meant for some versions of Windows.

    I added the registry keys above with value 2 and that removed the LSA warning and the LSASS.exe started event now shows up.

    Sometimes it says TPM not found, but on other boots it's OK and says the device meets the requirements for enhanced security.

    So it's still not a very good situation and not easy to sort out for a lot of users.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments