That error is because Credential Guard is licensed only for Enterprise and Education version of Windows 11. Change your KEY to an Enterprise version of Windows
How to fix LSA package is not signed as expected event log entries?
The home (non-work) desktop was upgraded yesterday to Windows 11 Pro 22H2 and afterwards on every boot there are several errors about LSA package is not signed as expected. How do I fix these errors? The desktop has Secure boot enabled with virtual based security enabled for memory protection. The CPU is an Intel i7 8700K, which meets Microsoft's requirements for Windows 11.
Windows for home | Windows 11 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
85 answers
Sort by: Oldest
-
Anonymous
2023-04-01T01:14:54+00:00 -
Anonymous
2023-04-01T02:16:53+00:00 Thank you for pointing out the licensing of Credential Guard - I wasn't aware
I haven't found where my Windows 11 Pro license won't allow Credential Guard to run
I'll dig deeper - the only thing I'd found is CG is not turned on by default...
-
Anonymous
2023-04-01T02:36:09+00:00 That error is because Credential Guard is licensed only for Enterprise and Education version of Windows 11. Change your KEY to an Enterprise version of Windows
I’ve never owned either of those versions in Windows 10 or 11 or in fact any Windows version.
I’m on Win 11 Pro.
Microsoft said the issue would occur if a Win 11 version had been downgraded from Enterprise to Pro.
Not in my case and I get the error.
Why would I change my key to Enterprise !
-
Anonymous
2023-04-01T02:37:45+00:00 If you are seeing LSA errors for packages negoexts, kerberos, msv1_0, tspkg, pku2u, cloudap, wdigest, schannel, sfapm - it looks like you can ignore those, because they are related to password-based SSO, according to this. These specific warnings (they are not errors in the event viewer!) only indicate that something tried loading one of the affected protocols or it was just the general attempt to load the library. According to MS article, this only blocks SSO, not the whole protocols.
It is clear, that for these particular instances it would warrant Microsoft to write a more appropriate warning text, perhaps also indicating what was calling the library or whether it was a general load of the library during boot-up sequence.
I have not found a way to learn what is actually triggering these libraries/protocols, and what can be done to disable them, if that is safe enough for a particular system (because if they are in use, disabling them may affect other apps).
The most useful and sensible reply in this entire thread.
Thank you
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more