News: 1679516916

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft freaks out users with Windows 11 warning: 'LSA protection is off'

(2023/03/22)


A recent security update to Windows 11 has put the scare on some users by warning that Microsoft's Local Security Authority (LSA) feature is turned off and their system is vulnerable to attack.

The warnings are triggered by the KB5007651 update, according to Microsoft. In messages to Redmond's support sites and on Reddit, some users linked the problem to another update released March 14 – [1]KB5023706 – saying it started to appear for them after they installed that update.

However, Microsoft is pinpointing the problem as KB5007651, noting in the Windows Health Dashboard that even after the LSA protections are enabled, users may still get a prompt saying they need to restart their system.

[2]

"This issue affects only 'Update for Microsoft Defender Antivirus antimalware platform – KB5007651 (Version 1.0.2302.21002),'" the company [3]wrote . "All other Windows updates released on March 14, 2023 for affected platforms (KB5023706 and KB5023698), do not cause this issue."

Speaking of Microsoft... The IT giant's Loop app, a todo list manager that's kinda like Asana, is [4]available now as a public preview. This is supposed to help people juggle tasks, documents, and work.

Windows 11 users over the past week have responded to the problem, which only affects systems running Windows 11 versions 22H2 and 21H2, with a mixture of anger, frustration, and anxiety.

One user [5]complained in a message on a Microsoft support site that his Windows 11 system was "telling me that my local security authority protection is off and it won't let me do anything to fix it. I can't uninstall the update either. Why would you create an update that would leave your users vulnerable to attack? How am I supposed to work now without a computer?"

[6]

[7]

A poster on [8]Reddit wrote: "Basically a yellow triangle appeared on the Windows Security iron, a week ago. It says that Local Security Authority protection is off. Your device may be vulnerable. There is no option to turn the protection on in the Device Security panel, there is only 'dismiss' option. Is it a bug or is it something I should be worried about?

LSA is a key security process in Windows that addresses authentication and authorization through such tasks as verifying logon attempts, password changes, and creating access tokens. It's such an important security feature that Redmond [9]said earlier this month when releasing Windows 11 Insider Preview Build 25314 to the Canary Channel that it will make LSA protection a default feature.

[10]Microsoft to give more than microsecond's thought about your Windows 11 needs

[11]Microsoft's Copilot AI to pervade the whole 365 suite

[12]Windows 11 puts 'disgusting' Remote Mailslots protocol out of its misery

[13]Now Microsoft injects Copilot AI into Dynamics 365

Starting with an upgrade, "we will audit for a period of time to check for incompatibilities with LSA protection," wrote Amanda Langowski, principal product manager for the Windows Insider Program, and Brandon LeBlanc, senior program manager at Microsoft. "If we do not detect any incompatibilities, we will automatically turn on LSA Protection."

Microsoft said that if users have enabled LSA protection and have restarted their devices at least once, they can dismiss the alerts saying the LSA protection is off and ignore notifications prompting them to restart their systems.

[14]

The company also [15]showed how users can determine if LSA protection is enabled by checking the Event Viewer.

Microsoft is not recommending any other workaround for the problem and said it is working to fix the issue, with an update coming as soon as it's available. ®

Get our [16]Tech Resources



[1] https://support.microsoft.com/en-us/topic/march-14-2023-kb5023706-os-build-22621-1413-9d3f2de5-08e7-4462-8fba-d944201f4ae1

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZBuIlgEBPz0mx8bMt0eatwAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#3048msgdesc

[4] https://www.microsoft.com/en-us/microsoft-365/blog/2023/03/22/new-microsoft-loop-app-is-built-for-modern-co-creation/

[5] https://answers.microsoft.com/en-us/windows/forum/all/cumulative-updates-for-windows-10-and-windows-11/642e85bb-9933-4d98-839f-4a86e532a40b?page=2&ranMID=24542&ranEAID=kXQk6*ivFEQ&ranSiteID=kXQk6.ivFEQ-d4uHFA9TVVXNyhw71DF8fg&epi=kXQk6.ivFEQ-d4uHFA9TVVXNyhw71DF8fg&irgwc=1&OCID=AID2200057_aff_7593_1243925&tduid=(ir__cbfw3az01wkfbxr9y9bos1pnfu2x6kyb0vituokj00)(7593)(1243925)(kXQk6.ivFEQ-d4uHFA9TVVXNyhw71DF8fg)()&irclickid=_cbfw3az01wkfbxr9y9bos1pnfu2x6kyb0vituokj00

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBuIlgEBPz0mx8bMt0eatwAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBuIlgEBPz0mx8bMt0eatwAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.reddit.com/r/antivirus/comments/11uhokr/cant_enable_microsoft_vulnerable_driver_blocklist/

[9] https://blogs.windows.com/windows-insider/2023/03/08/announcing-windows-11-insider-preview-build-25314/

[10] https://www.theregister.com/2023/03/20/microsoft_windows_11_defaults/

[11] https://www.theregister.com/2023/03/16/microsoft_365_copilot_ai_teaser/

[12] https://www.theregister.com/2023/03/13/microsoft_remote_mailslots_out/

[13] https://www.theregister.com/2023/03/07/microsoft_dynamics365_copilot_ai/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBuIlgEBPz0mx8bMt0eatwAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#verifying-lsa-protection

[16] https://whitepapers.theregister.com/



stiine

Hey Microsoft, Stop beta-testing on the general public. Instead get your legal and finanace departments to patch and upgrade before you publish the updates to windows update.

You would think

aerogems

After they fired a bunch of the QA staff they started suffering more and more embarrassing gaffes with botched updates and other issues. The logical thing would seem to be to hire some of those people back. They may seem like a cost center to the beancounters, but if you drive away your paying customers with shoddy quality products, you won't have any of the revenue that they love so much.

Re: You would think

Terry 6

The problem is that Windows is still the automatic default OS for most people. They can't/won't pay the Apple tax and switch to fruit OS and have barely if at all heard of the 'Nuxes. And if they do, ordinary users aren't as enthusiastic about the idea of there being a squillion competing distros as commentards here might be. So Microsoft can push their appalling stupidity as far as they want to. If Win 8 didn't break them, this sort of thing certainly won't.

Re: You would think

aerogems

We individuals aren't really Microsoft's customer. We're incidental compared to large corporations who buy expensive volume license packages for multiple products. You start making Exchange or SQL Server patches that are flaky and that's how you get ants Google and or Oracle sniffing around looking to poach a customer.

nothing to worry about folks.

Omnipresent

Just the AI pushing code onto stack over flow to test what it can get away with.

Kev99

How many years has mictosoft been pushing windows out? How many patches/bug fixes/updates (they're all the same at mictosoft) have they pushed out? And they STILL can get a fully functional, stable and reliable OS to the masses?

Cobol programmers are down in the dumps.