Update Windows 11 incorrectly warns Local Security Authority protection is off

BryanB

Level 23
Thread author
Verified
Top Poster
Well-known
Aug 17, 2017
1,227
Some users have reported that the Windows Security app is showing “Local Security authority protection is off. Your device may be vulnerable” warnings when the feature is enabled. This bug is in Windows Defender (KB5007651), a mandatory security update shipped alongside Windows 11’s March 2023 Update. Local Security Authority protection is a feature that prevents code injection and reduces the possibility of compromising credentials. The Local Security Authority feature verifies Windows logins, and it is necessary for the OS to function normally.
 

Oerlink

Level 11
Dec 24, 2022
510
Nah, nothing wrong with Microsoft products... but look out for TikTok, et al.
A missing registry key (trivial to fix) is not equivalent to a hypothetical threat of the CCP appropriating TikTok.

That's not the real TikTok threat. The real threat is that TikTok makes the world's children, teenagers and adults more stupid, mentally ill and addicted by the day.




 

Malleable

Level 1
Mar 2, 2021
46
I received this taskbar icon warning. In my case I think I read it was Core Isolation>Memory Integrity was off or it was on and I turned it off then back on and the warning on my taskbar icon went away. I toggled it on, rebooted numerous times since then, and still see the red "This change requires you to restart your device." notification while it's still on.
 
  • Like
Reactions: plat and BryanB

oldschool

Level 74
Verified
Top Poster
Well-known
Mar 29, 2018
6,395
I received this taskbar icon warning. In my case I think I read it was Core Isolation>Memory Integrity was off or it was on and I turned it off then back on and the warning on my taskbar icon went away. I toggled it on, rebooted numerous times since then, and still see the red "This change requires you to restart your device." notification while it's still on.
Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"RunAsPPL"=dword:00000002
"RunAsPPLBoot"=dword:00000002
 

plat

Level 28
Verified
Top Poster
Well-known
Sep 13, 2018
1,797
I'm just gonna leave it b/c acc. to the Bleeping article posted here, if it's toggled to "on" it's "on" regardless of the warning. I toggled it and now I have this silly thing here in spoiler. This drive isn't running very often anyway, just to update software like VoodooShield.


"There is a technical glitch with this feature, if you have successfully turned on this feature and you are being prompted to restart, kindly note that the feature is ON irrespective of the message as this is a technical glitch that we are aware of and we are working to resolve that issue soonest," Microsoft Technical support representative reportedly told one of the affected users.

lsas notice.png

:):coffee:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top