The Local Security Authority protection is off - Windows 11 Home

Anonymous
2023-03-17T06:10:20+00:00

A yellow triangle appeared on the Windows Security iron yesterday. It says that Local Security Authority protection is off. Your device may be vulnerable.

I can press Go to settings or Dismiss but when I click go to settings, a notification saying "the page You want to access doesn't contain required functions and is unavailable". 

There is also no option to turn the protection on in the Device Security panel (there is only "dismiss" option).

When I was looking at it yesterday, there was also a notification that "The tpm module is unavailable" but today it doesn't show. I checked the device manager and uefi and both say that the tpm is enabled.

I've found an advice to turn on SMV in UEFI (in the CPU settings) to solve the problem but I don't want to change anything in BIOS without consultation as I'm no expert. I've also found a reply from a truste source that this whole problem is a Microsoft bug and it's better to just wait till they fix it.

What should I do?

Screenshots are in Polish, I hope they can be useful somehow. The first one shows the notification about a page being not available and the second shows the Device security panel (the notification from the first screenshot displays when I close the device security page or when I click on "go to settings" below the information that the protection is turned off). There is also an information (second screenshot) that "standard device security is not supported".

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-07-06T07:36:56+00:00

Microsoft have just posted that they have resolved the "Local Security Authority protection is off" issue in an update. Has anyone tried to apply it from Windows Update?

Resolution: This issue was resolved in an update for Windows Security platform antimalware platform KB5007651 (Version 1.0.2306.10002). If you would like to install the update before it is installed automatically, you will need to check for updates.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

174 additional answers

Sort by: Oldest
  1. Anonymous
    2023-05-04T22:21:57+00:00

    Haha, yes. It is the Beta Program.

    I know it is not ideal, but it was a good work-around until they finally released the fix. I forget which update it was now, as they've released a few these past couple of months but it has been addressed, except for the Signature/Certificate issue. That is minor, but should be addressed or the service could be used by malicious code.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-05-04T22:37:20+00:00

    The 1st thing you want to do is make sure you have the most up to date BIOS and Drivers for your Motherboard/Chipset.
    If that doesn't resolve it:

    As you mentioned, make sure TPM is enabled in the BIOS.

    Next, make sure your OS is completely up-to-date, and notate the Build Version.

    Follow previous posts for EventViewer Errors pertaining to LSA and TPM module.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-05-04T22:53:46+00:00

    Not sure how to check the BIOS, my build is 22621.1555

    There is a cumulative update preview for Windows 11 Version 22H2 for x64-based Systems (KB5025305) is available in windows update right now. Will this fix this?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-05-04T23:37:37+00:00

    KB 5025305 should bring your build up to what you see here, even on Win 10. Microsoft is funny, same builds, "Different OS's". It's more like, "Different Experience Packs". The main build is the same for both. ImageAs for LSA being "Fixed". Well, it is for the most part. It works. You will still have the "Warning" and "This change requires you to restart your device." message. However, you can tell it is actually working by checking in the EventViewer logs. If there are no warnings displayed for LSA in any of the EV Categories within the Snap-In for EV, this means that the feature is indeed working (according to MSFT). Mine gives the warning still, but all testing proves it to be functional. The ticker also stays ticked after reboot. It seems the software isn't sending the flag that it has been set to "On", to remove the warning flag.

    Image

    Was this answer helpful?

    0 comments No comments