The Windows process responsible for authenticating sign-ins, which keeps credentials in memory and is therefore a favourite target for credential theft. An attack surface reduction rule guards it, though that rule adds nothing once LSA protection is enabled.
Also called Local Security Authority Subsystem Service.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains LSASS in context, with comparison tables and the common traps.
Terms in this definition
- RACI
Stands for responsible, accountable, consulted, informed. A RACI chart lists functions and shows, for each, the single team accountable and the teams in the other three roles; the Cloud Adoption Framework includes worked examples.
- Attack surface reduction
Protections in Defender for Endpoint that close off behaviour attackers like to abuse. Chief among them are ASR rules, which on Windows can stop Office programs spawning child processes or obfuscated scripts from running.
- LSA protection
Turns LSASS into a protected process. Code that isn't trusted then cannot inject into it or inspect its memory.
Related terms
- LSA
Local Security Authority. Running as LSASS, it verifies sign-ins made locally or over the network and applies local security policy; its stored secrets can be shielded with Credential Guard and LSA protection.
- PPL
Protected Process Light: a Windows protection level that LSA protection relies on so that LSASS memory can be reached only by other protected processes.
- Standard protection rules
Attack surface reduction rules Microsoft suggests turning on in block mode after only light testing, for example stopping credential theft from LSASS or misuse of vulnerable signed drivers.