GPO policy: "Configures LSASS to run as a protected process" under Computer Configuration > Administrative Templates > System > Local Security Authority. Controls whether the Local Security Authority Subsystem Service (LSASS / lsass.exe) runs as a Protected Process Light (PPL), which prevents non-protected processes from reading LSASS memory or injecting code (credential theft defense). Registry: HKLM\SYSTEM\CurrentControlSet\Control\Lsa:RunAsPPL (REG_DWORD). Automatically enabled (value 2, without UEFI lock) on new installations of Windows 11 22H2+ on eligible domain-joined devices. CIS Benchmark (L1) recommends value 1 (with UEFI lock). Reference: Configuring Additional LSA Protection
Values
| Enum Value | Description |
|---|---|
|
|
LSA not run as PPL (registry value 0). LSASS runs as a normal process; credentials may be read by tools like Mimikatz. |
|
|
LSA run as PPL with UEFI lock (registry value 1). LSASS runs as a Protected Process Light and the configuration is stored in a UEFI variable. Cannot be disabled without physical access to clear the UEFI variable. CIS L1 recommended value. |
|
|
LSA run as PPL without UEFI lock (registry value 2). LSASS runs as a Protected Process Light but the setting is not stored in UEFI firmware. Can be disabled remotely via registry or policy. Default on Windows 11 22H2+ new installations. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"DISABLED"