Windows Security Bug - Local Security Authority Protection Not Registering a System Restart

Anonymous
2023-01-15T20:14:29+00:00

After I uninstalled Avira Antimalware, I got an alert from Windows Security that my Local Security Authority Protection was turned off. But after I turned it on and restarted as instructed, I continue to get the same alert that my Local Security Authority Protection is turned off, even though within the same window, the toggle switch under the "Local Security Authority Protection" heading displays that it's already turned on.

Additionally, at the same time that this bug appeared, I've also started to get an old Windows bug where if I try to open File Explorer from the taskbar, the entire taskbar would crash and restart every time (though I can open File Explorer from the Start menu without issue).

Any help resolving either bug would be appreciated. Thanks.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-02-23T14:51:38+00:00

I figure that is a missing reg entry RunAsPPLBoot in my case.

Create a new DWORD32 and set to 2

After reboot no longer get error.

RunAsPPL and RunAsPPLBoot.

By default they are set to 0 to enable this you need to set them to 2.

Also set group policy as enable for uefi lock only , my problem is fixed now, no need to reset windows.

In the Local Group Policy Editor window, navigate to the following path: Computer Configuration\Administrative Templates\System\Local Security Authority.

In the right panel, double-click on the ‘Configure LSASS to run as a protected process‘ policy.

In the policy settings window, select the Enabled option

Then click on the dropdown under Configure LSA to run as a protected process and select Enabled with UEFI Lock

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-03-17T11:31:41+00:00

    Hi, Jethro1955

    That issue (Standard hardware security not supported), from what I've been researching, is caused by an Update for Windows Security Platform.

    It appears that Windows 11 22H2 (build 22621) is not compatible with a previously installed Windows Security Platform update in version 22H1 (build 22000). Although this does not affect all computers because it largely depends on the installed hardware and BIOS settings, as well as the type of installation: in a clean installation there is no such problem.

    Specifically, it is the KB5007651 update, May 2022 for Windows 11 22H1, which already had many installation problems at the time. Logically, the computers updated after Windows 11 22H2 maintain that update that is now not compatible and that causes this problem in Windows Security.

    The ideal solution has to be implemented by Microsoft through a new update for the Windows Security Platform for Windows 11 22H2.

    However, there is a workaround until Microsoft releases the new update: delete the KB5007651 update folder:

    1. Access the following path: C:\Windows\System32\SecurityHealth
    2. Delete the folder 1.0.2109.27002-0 with all its content (be careful with deleting other folders)
    3. Reboot the system.

    If no folder appears in that location, you can try reinstalling Windows Security Platform with the new update. Download from this link the folder that contains the application:

    https://app.box.com/s/8br9g6arlce8pgxx5hmh6t1jcv4zj2s0

    Now follow these steps:

    1. Create a restore point first
    2. Unzip the downloaded ZIP file on the Desktop
    3. Navigate to the location C:\Windows\System32\SecurityHealth to take ownership of that folder:

    Properties > Security > Advanced Options > Change > Administrators

    Check the "Replace owner on subcontainers and objects" box and click Apply.

    In the "SecurityHealth Permissions" window select Administrators > Full Control. Apply.

    1. Copy the "1.0.2207.20002-0" folder on the Desktop to the SecurityHealth folder
    2. Open the folder and run the application "Microsoft.SecHealthUI_8wekyb3d8bbwe.appx" as administrator to update.
    3. Restart the computer.

    Tell us if it worked

    Note: make these settings at your own risk.

    my folder is 1.0.2302.21002-0 so that won't work for me

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-03-17T11:27:32+00:00

    I figure that is a missing reg entry RunAsPPLBoot in my case.

    Create a new DWORD32 and set to 2

    After reboot no longer get error.

    RunAsPPL and RunAsPPLBoot.

    By default they are set to 0 to enable this you need to set them to 2.

    Also set group policy as enable for uefi lock only , my problem is fixed now, no need to reset windows.

    In the Local Group Policy Editor window, navigate to the following path: Computer Configuration\Administrative Templates\System\Local Security Authority.

    In the right panel, double-click on the ‘Configure LSASS to run as a protected process‘ policy.

    In the policy settings window, select the Enabled option

    Then click on the dropdown under Configure LSA to run as a protected process and select Enabled with UEFI Lock

    Thank you, this fixed it for me, I am getting fed up with Microsoft breaking things.

    it's not a fix but a bypass for now

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-03-17T11:20:38+00:00

    I figure that is a missing reg entry RunAsPPLBoot in my case.

    Create a new DWORD32 and set to 2

    After reboot no longer get error.

    RunAsPPL and RunAsPPLBoot.

    By default they are set to 0 to enable this you need to set them to 2.

    Also set group policy as enable for uefi lock only , my problem is fixed now, no need to reset windows.

    In the Local Group Policy Editor window, navigate to the following path: Computer Configuration\Administrative Templates\System\Local Security Authority.

    In the right panel, double-click on the ‘Configure LSASS to run as a protected process‘ policy.

    In the policy settings window, select the Enabled option

    Then click on the dropdown under Configure LSA to run as a protected process and select Enabled with UEFI Lock

    Thank you, this fixed it for me, I am getting fed up with Microsoft breaking things.

    Was this answer helpful?

    0 comments No comments
  4. Enric Cortés 39,445 Reputation points Volunteer Moderator
    2023-03-17T11:10:02+00:00

    Hi, Jethro1955

    That issue (Standard hardware security not supported), from what I've been researching, is caused by an Update for Windows Security Platform.

    It appears that Windows 11 22H2 (build 22621) is not compatible with a previously installed Windows Security Platform update in version 22H1 (build 22000). Although this does not affect all computers because it largely depends on the installed hardware and BIOS settings, as well as the type of installation: in a clean installation there is no such problem.

    Specifically, it is the KB5007651 update, May 2022 for Windows 11 22H1, which already had many installation problems at the time. Logically, the computers updated after Windows 11 22H2 maintain that update that is now not compatible and that causes this problem in Windows Security.

    The ideal solution has to be implemented by Microsoft through a new update for the Windows Security Platform for Windows 11 22H2.

    However, there is a workaround until Microsoft releases the new update: delete the KB5007651 update folder:

    1. Access the following path: C:\Windows\System32\SecurityHealth
    2. Delete the folder 1.0.2109.27002-0 with all its content (be careful with deleting other folders)
    3. Reboot the system.

    If no folder appears in that location, you can try reinstalling Windows Security Platform with the new update. Download from this link the folder that contains the application:

    https://app.box.com/s/8br9g6arlce8pgxx5hmh6t1jcv4zj2s0

    Now follow these steps:

    1. Create a restore point first
    2. Unzip the downloaded ZIP file on the Desktop
    3. Navigate to the location C:\Windows\System32\SecurityHealth to take ownership of that folder:

    Properties > Security > Advanced Options > Change > Administrators

    Check the "Replace owner on subcontainers and objects" box and click Apply.

    In the "SecurityHealth Permissions" window select Administrators > Full Control. Apply.

    1. Copy the "1.0.2207.20002-0" folder on the Desktop to the SecurityHealth folder
    2. Open the folder and run the application "Microsoft.SecHealthUI_8wekyb3d8bbwe.appx" as administrator to update.
    3. Restart the computer.

    Tell us if it worked

    Note: make these settings at your own risk.

    Was this answer helpful?

    0 comments No comments