Endpoint configuration · GraphQL enum

RunAsPPL enum

GPO policy: "Configures LSASS to run as a protected process" under Computer Configuration > Administrative Templates > System > Local Security Authority. Controls whether the Local Security Authority Subsystem Service (LSASS / lsass.exe) runs as a Protected Process Light (PPL), which prevents non-protected processes from reading LSASS memory or injecting code (credential theft defense). Registry: HKLM\SYSTEM\CurrentControlSet\Control\Lsa:RunAsPPL (REG_DWORD). Automatically enabled (value 2, without UEFI lock) on new installations of Windows 11 22H2+ on eligible domain-joined devices. CIS Benchmark (L1) recommends value 1 (with UEFI lock). Reference: Configuring Additional LSA Protection

Values

Enum Value Description

DISABLED

LSA not run as PPL (registry value 0). LSASS runs as a normal process; credentials may be read by tools like Mimikatz.

ENABLED_WITH_UEFI_LOCK

LSA run as PPL with UEFI lock (registry value 1). LSASS runs as a Protected Process Light and the configuration is stored in a UEFI variable. Cannot be disabled without physical access to clear the UEFI variable. CIS L1 recommended value.

ENABLED_WITHOUT_LOCK

LSA run as PPL without UEFI lock (registry value 2). LSASS runs as a Protected Process Light but the setting is not stored in UEFI firmware. Can be disabled remotely via registry or policy. Default on Windows 11 22H2+ new installations.

Used by

Example

Example

"DISABLED"