Windows Security Bug - Local Security Authority Protection Not Registering a System Restart

Anonymous
2023-01-15T20:14:29+00:00

After I uninstalled Avira Antimalware, I got an alert from Windows Security that my Local Security Authority Protection was turned off. But after I turned it on and restarted as instructed, I continue to get the same alert that my Local Security Authority Protection is turned off, even though within the same window, the toggle switch under the "Local Security Authority Protection" heading displays that it's already turned on.

Additionally, at the same time that this bug appeared, I've also started to get an old Windows bug where if I try to open File Explorer from the taskbar, the entire taskbar would crash and restart every time (though I can open File Explorer from the Start menu without issue).

Any help resolving either bug would be appreciated. Thanks.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-02-23T14:51:38+00:00

I figure that is a missing reg entry RunAsPPLBoot in my case.

Create a new DWORD32 and set to 2

After reboot no longer get error.

RunAsPPL and RunAsPPLBoot.

By default they are set to 0 to enable this you need to set them to 2.

Also set group policy as enable for uefi lock only , my problem is fixed now, no need to reset windows.

In the Local Group Policy Editor window, navigate to the following path: Computer Configuration\Administrative Templates\System\Local Security Authority.

In the right panel, double-click on the ‘Configure LSASS to run as a protected process‘ policy.

In the policy settings window, select the Enabled option

Then click on the dropdown under Configure LSA to run as a protected process and select Enabled with UEFI Lock

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

138 additional answers

Sort by: Newest
  1. Anonymous
    2023-05-04T16:32:23+00:00

    It's back ... as of this morning ... right after the following automatic update "Update for Windows Security platform antimalware platform - KB5007651 (Version 1.0.2303.28002) Successfully installed on May 4, 2023"

    I note that the "fix" for this Issue "Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001)" that originally corrected this error for me when it first automatically installed on April 18th is now showing in the Event Viewer as having successfully re-installed itself a few times more times over the last few hours AFTER Update for Windows Security platform antimalware platform - KB5007651 (Version 1.0.2303.28002) automatically installed earlier this morning BUT it does not appear to have resolved the Issue this time.

    Anyone else out there experiencing this very same thing again? I am confused ...

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-04-29T16:35:36+00:00

    This was resolved by KB5007651 (Version 1.0.2303.27001).

    Check your Windows Update history under Definition Updates to see what version you have.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-04-29T16:10:56+00:00

    I have had this problem with "Local Security Authority" since March 14th and a little yellow exclamation mark inside of "Windows Security" Tray icon. I just happened to click on that tray icon today (April 29th) and it gave me a different message related to "Core Isolation" not being turned on. I turned that setting on and rebooted. FINALLY the little yellow exclamation mark inside of Windows Security Tray icon disappeared!

    Problem Solved!

    BUT, now I can not even find "Local Security Authority" within Windows settings. Did MS replace it or get rid of it? Pretty sure that Core Isolation has been around for awhile, but not positive.

    NOTE: I did not do any Windows updates since April 11th.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-04-11T23:57:14+00:00

    This reinforces my belief that the RunAsPPLBoot workaround, which Microsoft advises against, is a bad idea. If the solution really was as simple as setting a missing registry value, it would have been done on patch Tuesday.

    Was this answer helpful?

    0 comments No comments