Turns LSASS into a protected process. Code that isn't trusted then cannot inject into it or inspect its memory.
Also called RunAsPPL.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains LSA protection in context, with comparison tables and the common traps.
Terms in this definition
- LSASS
The Windows process responsible for authenticating sign-ins, which keeps credentials in memory and is therefore a favourite target for credential theft. An attack surface reduction rule guards it, though that rule adds nothing once LSA protection is enabled.
Related terms
- LSA
Local Security Authority. Running as LSASS, it verifies sign-ins made locally or over the network and applies local security policy; its stored secrets can be shielded with Credential Guard and LSA protection.
- PPL
Protected Process Light: a Windows protection level that LSA protection relies on so that LSASS memory can be reached only by other protected processes.