Windows Security Bug - Local Security Authority Protection Not Registering a System Restart

Anonymous
2023-01-15T20:14:29+00:00

After I uninstalled Avira Antimalware, I got an alert from Windows Security that my Local Security Authority Protection was turned off. But after I turned it on and restarted as instructed, I continue to get the same alert that my Local Security Authority Protection is turned off, even though within the same window, the toggle switch under the "Local Security Authority Protection" heading displays that it's already turned on.

Additionally, at the same time that this bug appeared, I've also started to get an old Windows bug where if I try to open File Explorer from the taskbar, the entire taskbar would crash and restart every time (though I can open File Explorer from the Start menu without issue).

Any help resolving either bug would be appreciated. Thanks.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-02-23T14:51:38+00:00

I figure that is a missing reg entry RunAsPPLBoot in my case.

Create a new DWORD32 and set to 2

After reboot no longer get error.

RunAsPPL and RunAsPPLBoot.

By default they are set to 0 to enable this you need to set them to 2.

Also set group policy as enable for uefi lock only , my problem is fixed now, no need to reset windows.

In the Local Group Policy Editor window, navigate to the following path: Computer Configuration\Administrative Templates\System\Local Security Authority.

In the right panel, double-click on the ‘Configure LSASS to run as a protected process‘ policy.

In the policy settings window, select the Enabled option

Then click on the dropdown under Configure LSA to run as a protected process and select Enabled with UEFI Lock

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-05-05T19:54:04+00:00

    I can confirm its repeating the install of that Definition Update like about every 8 mins.

    Installation Started: Windows has started installing the following update: Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001)

    Installation Successful: Windows successfully installed the following update: Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001)

    I think this is happening due to its not the latest version, Microsoft needs to remove that from their library until the issue has been resolved.

    And on top of that, I think they need to clean up old installs due to I still have several old versions of Security Health and I shouldn't have to keep doing clean installs to clean up after them.

    Oh and you can see several LSA (LsaSrv) Logs for Events 6156 along with loads of LSA Warnings with EventID 6155 in the Event Viewer when it boots up.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-05-05T12:59:08+00:00

    Yes ... I also did get the Update for Windows Security platform antimalware platform - KB5007651 (Version 1.0.2303.28002) yesterday morning and I believe that this caused this very same Issue (Warning that the Local Area Security is off and that my device may be vulnerable) to start showing up again in Device Security as well as for that annoying little yellow exclamation mark inside of "Windows Security" Tray icon.

    Yes ... they then did roll back to the Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001) after this and this one keeps re-installing on its own over the last 24 hour period, over and over again ... automatically or if I manually search for Windows Updates. It is like it is continually trying to correct this Warning Issue once again as it did for me when it first installed on my desktop on April 18th but the warnings do not go away.

    As per Microsoft's Bulletin opened on March 21st and now closed on May 3rd ... "Verifying LSA protection To discover if LSA was started in protected mode when Windows started, search for the following Wininit event in the System log under Windows Logs:12: LSASS.exe was started as a protected process with level: 4" I can, in fact, see this in the Event Viewer but only when I perform a Re-Start and not when I Start up the Desktop after a complete Shut down. I would think that this should appear in the Event Viewer in either scenario but I have ASSUMED this means that LSA is actually working on my Desktop despite these warnings that have come back.

    Still very confused ...

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-05-05T04:47:53+00:00

    They rolled it back to Update for Microsoft Defender Antivirus antimalware platform - KB5007651 (Version 1.0.2303.27001) just now.

    Yesterday I got the Update for Windows Security platform antimalware platform - KB5007651 (Version 1.0.2303.28002) so you may need to recheck for updates.

    Hopefully they don't make this mistake in the future.

    I am just hoping they fix the following issue which happens now and then when I open Device security : The Windows Security Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Faulting application name: SecurityHealthService.exe, version: 10.0.22621.1635, time stamp: 0xc9cb2878Faulting module name: ntdll.dll, version: 10.0.22621.1485, time stamp: 0xb7f0154a

    Code Integrity determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume9\Windows\System32\fcon.dllAll 3 errors are linked and happened at the exact same time.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-05-04T18:36:39+00:00

    It's back ... as of this morning ... right after the following automatic update "Update for Windows Security platform antimalware platform - KB5007651 (Version 1.0.2303.28002) Successfully installed on May 4, 2023"

    Yes, it seems like the Windows Security team has a serious quality control problem.

    Was this answer helpful?

    0 comments No comments