How to fix LSA package is not signed as expected event log entries?

Anonymous
2022-09-21T15:03:13+00:00

The home (non-work) desktop was upgraded yesterday to Windows 11 Pro 22H2 and afterwards on every boot there are several errors about LSA package is not signed as expected. How do I fix these errors? The desktop has Secure boot enabled with virtual based security enabled for memory protection. The CPU is an Intel i7 8700K, which meets Microsoft's requirements for Windows 11.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

85 answers

Sort by: Most helpful
  1. Anonymous
    2022-11-09T14:00:00+00:00

    I used the "Using Local Group Policy on Windows 11, 22H2" from the article you provided: Configuring Additional LSA Protection | Microsoft Learn

    I set the "Enabled with UEFI Lock" option

    Still getting 10 errors as before

    As of 11/1 I'm now getting: Event 6147, LSA (LsaSrv) : Credential Guard is configured to run, but is not licensed. Credential Guard was not started.

    (The only system changes were Windows Update "Dell, Inc. - Firmware - 0.1.19.0")

    Was hoping the Windows Updates applied last night would help...

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-11-03T02:46:38+00:00

    That's odd, it instantly solved all of mine.

    Since it was a USB device, try unplugging all nonessential USB accessories, I would bet it's the fob.

    If it reboots with no LSA error without the USB accessories you might need that reg key and a viable driver.

    Driver files did change a bit and require WHQL drivers for most devices. My headset, which this registry key fixed the LSA for, did recently update theirs for certification.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-11-02T11:55:58+00:00

    Solved.

    ...

    The device that was causing the issue for me was a G935 Gaming Headset, which re-prompted to select the device after I created the key and rebooted.

    Sadly, in my case this didn't work. Still throwing 10+ LSA errors despite setting that key, and with only a card reader(fob) that's got signed drivers, at this point I'm looking at throwing my hands up in the air and hoping that MS sometime, in the future, will actually fix this.

    It really doesn't cause me any huge problems, since said work machine 2 is already network isolated but still...irritation at it. At least it's not as bad as the softmodem fiasco with Win95. Anyway to those throwing hints, at least for me I give thanks for something to try.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2022-10-21T17:38:21+00:00

    Try setting a password.

    I know its something to do with the user account controls from an update, possibly to the Group Policies, and since 11 is working on being more secure, I think it is trying to force specific user account controls.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2022-10-21T17:08:50+00:00

    It's something in the user account controls.

    Do these both have local Admin accounts enabled or multiple user accounts?

    Unfortunately, the person who did a new build didn't respond as to whether it was an upgrade or a fresh install since an upgrade from 10 might have the local admin enabled.

    I logged into the local admin on mine and saw an error about the password change requirement, which was previously set to never expire, so I am leaning towards a change in the group policy from the update. After I reset the policies, just through the user account control, to never expire password, etc. I haven't had further issues.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments