---
title: RunAsPPL enum | Wartiva GraphQL API
description: GPO policy: "Configures LSASS to run as a protected process" under Computer Configuration > Administrative Templates > System > Local Security Authority.
url: https://wartiva.com/api-docs/types/run-as-ppl.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `RunAsPPL` enum

GPO policy: "Configures LSASS to run as a protected process" under Computer Configuration > Administrative Templates > System > Local Security Authority. Controls whether the Local Security Authority Subsystem Service (LSASS / lsass.exe) runs as a Protected Process Light (PPL), which prevents non-protected processes from reading LSASS memory or injecting code (credential theft defense). Registry: HKLM\SYSTEM\CurrentControlSet\Control\Lsa:RunAsPPL (REG_DWORD). Automatically enabled (value 2, without UEFI lock) on new installations of Windows 11 22H2+ on eligible domain-joined devices. CIS Benchmark (L1) recommends value 1 (with UEFI lock). Reference: [Configuring Additional LSA Protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)

## Values

| Enum Value | Description |
|---|---|
| `DISABLED` | LSA not run as PPL (registry value 0). LSASS runs as a normal process; credentials may be read by tools like Mimikatz. |
| `ENABLED_WITH_UEFI_LOCK` | LSA run as PPL with UEFI lock (registry value 1). LSASS runs as a Protected Process Light and the configuration is stored in a UEFI variable. Cannot be disabled without physical access to clear the UEFI variable. CIS L1 recommended value. |
| `ENABLED_WITHOUT_LOCK` | LSA run as PPL without UEFI lock (registry value 2). LSASS runs as a Protected Process Light but the setting is not stored in UEFI firmware. Can be disabled remotely via registry or policy. Default on Windows 11 22H2+ new installations. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"DISABLED"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
