Windows Security Bug - Local Security Authority Protection Not Registering a System Restart

Anonymous
2023-01-15T20:14:29+00:00

After I uninstalled Avira Antimalware, I got an alert from Windows Security that my Local Security Authority Protection was turned off. But after I turned it on and restarted as instructed, I continue to get the same alert that my Local Security Authority Protection is turned off, even though within the same window, the toggle switch under the "Local Security Authority Protection" heading displays that it's already turned on.

Additionally, at the same time that this bug appeared, I've also started to get an old Windows bug where if I try to open File Explorer from the taskbar, the entire taskbar would crash and restart every time (though I can open File Explorer from the Start menu without issue).

Any help resolving either bug would be appreciated. Thanks.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-02-23T14:51:38+00:00

I figure that is a missing reg entry RunAsPPLBoot in my case.

Create a new DWORD32 and set to 2

After reboot no longer get error.

RunAsPPL and RunAsPPLBoot.

By default they are set to 0 to enable this you need to set them to 2.

Also set group policy as enable for uefi lock only , my problem is fixed now, no need to reset windows.

In the Local Group Policy Editor window, navigate to the following path: Computer Configuration\Administrative Templates\System\Local Security Authority.

In the right panel, double-click on the ‘Configure LSASS to run as a protected process‘ policy.

In the policy settings window, select the Enabled option

Then click on the dropdown under Configure LSA to run as a protected process and select Enabled with UEFI Lock

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

138 additional answers

Sort by: Newest
  1. Anonymous
    2023-05-26T22:38:50+00:00

    I'm trying these steps but why I don't have the RunAsPPL on the right panel?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-05-08T06:09:49+00:00

    In those security settings you can expand for more information and view what drivers are incompatible and force uninstall them with a pnputil command in CMD.

    Make sure these drivers are old or obsolete and not necessary. If these are important drivers there's nothing you can do exept contacting the official manufacturer so they can develop a sollution.

    for instance

    pnputil /delete-driver oem44.inf /uninstall /force

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-05-05T19:54:04+00:00

    I can confirm its repeating the install of that Definition Update like about every 8 mins.

    Installation Started: Windows has started installing the following update: Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001)

    Installation Successful: Windows successfully installed the following update: Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001)

    I think this is happening due to its not the latest version, Microsoft needs to remove that from their library until the issue has been resolved.

    And on top of that, I think they need to clean up old installs due to I still have several old versions of Security Health and I shouldn't have to keep doing clean installs to clean up after them.

    Oh and you can see several LSA (LsaSrv) Logs for Events 6156 along with loads of LSA Warnings with EventID 6155 in the Event Viewer when it boots up.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-05-05T12:59:08+00:00

    Yes ... I also did get the Update for Windows Security platform antimalware platform - KB5007651 (Version 1.0.2303.28002) yesterday morning and I believe that this caused this very same Issue (Warning that the Local Area Security is off and that my device may be vulnerable) to start showing up again in Device Security as well as for that annoying little yellow exclamation mark inside of "Windows Security" Tray icon.

    Yes ... they then did roll back to the Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001) after this and this one keeps re-installing on its own over the last 24 hour period, over and over again ... automatically or if I manually search for Windows Updates. It is like it is continually trying to correct this Warning Issue once again as it did for me when it first installed on my desktop on April 18th but the warnings do not go away.

    As per Microsoft's Bulletin opened on March 21st and now closed on May 3rd ... "Verifying LSA protection To discover if LSA was started in protected mode when Windows started, search for the following Wininit event in the System log under Windows Logs:12: LSASS.exe was started as a protected process with level: 4" I can, in fact, see this in the Event Viewer but only when I perform a Re-Start and not when I Start up the Desktop after a complete Shut down. I would think that this should appear in the Event Viewer in either scenario but I have ASSUMED this means that LSA is actually working on my Desktop despite these warnings that have come back.

    Still very confused ...

    Was this answer helpful?

    0 comments No comments