False error on Local Security Authority Protection [Windows 11]


Recommended Posts

My Windows 11 Security states that there are errors on my Local Security Authority Protection.

The info that is given is that no TPM it there. Yet, there is.

image.png.7977590e99989ac5b1985d783f5f1b8e.png

 

I also got this message on other (Intel) computer, and after checking and double-checking I decided to Dismiss this error.

Is this a (known) bug on Windows 11, 22H2 with all latest updates installed?

image.png

image.png

  • kiddingguy changed the title to False error on Local Security Authority Protection [Windows 11]
On 04/05/2023 at 07:11, Ixion said:

Yup, it's a known bug and there have been several Neowin articles about it. I thought that a fix had been released but it may be limited to release preview or beta builds for the moment.

Fairly sure it's unfixed in Beta.

On 04/05/2023 at 07:11, Ixion said:

Yup, it's a known bug and there have been several Neowin articles about it. I thought that a fix had been released but it may be limited to release preview or beta builds for the moment.

they did release a fix, but that fix recently broke again from what I heard :D 

On 07/05/2023 at 21:10, skinnyJM said:

Yes, it's back, returned to both of my (officially supported) W11 machines yesterday, but not the unofficially supported one. So I'm not sure what's going on there...

I guess it's the Microsoft way of "fixing".

1. It works
2. Let's break it with an update
3. Let's fix it
4. Let's break it again
5. Let's fix it with another update

(repeat steps 4 & 5 indefinitely) 

I think the OP is experiencing two different bugs here. The article that is posted here in Neowin relates to the error with the Local Security Authority Protection bein off. ( I even experienced that myself, but it was fixed in one of my PCs, yet not in the other). Yet the OP is seeing an error related to no TPM module detected as well.

OP might want to refresh his Windows TPM settings.  Here's how.

Additionally you might want to make sure Secure Boot is enabled on your BIOS / UEFI.

Because I have Linux also installed in dual boot and have disabled Secure Boot at times, I have then experienced that TPM error on Windows 11.

On 08/05/2023 at 19:01, Elі said:

I think the OP is experiencing two different bugs here. The article that is posted here in Neowin relates to the error with the Local Security Authority Protection bein off. ( I even experienced that myself, but it was fixed in one of my PCs, yet not in the other). Yet the OP is seeing an error related to no TPM module detected as well.

OP might want to refresh his Windows TPM settings.  Here's how.

Additionally you might want to make sure Secure Boot is enabled on your BIOS / UEFI.

Because I have Linux also installed in dual boot and have disabled Secure Boot at times, I have then experienced that TPM error on Windows 11.

TPM is on.

It's the message in Windows Security that tells me it's off [not true]. And the bug came back.

On 09/05/2023 at 16:29, skinnyJM said:

I'm seeing the same exact screens, preceded by:

image.jpeg.07c63e792865f014de9a89108e499378.jpeg

Yes, MS doing what they do best. They break something, fix it, and then break it again later.

 

But with MS being a small indie developer, its to be expected. /s

See frontpage news:   Microsoft admits it couldn't really fix Windows 11 Security and Defender LSA issues :D

And my question: Is disabling kernel mode better than just click “ Dismiss” and not be bothered by this message?
For security-sake I mean...

The issue for some people appears to be that it's causing a BSOD rather than just an annoying message so disabling Kernal mose is a sensible setp. Personally I use my machine primarily for gaming and most of the virtualisation based security (kernel mode isolation, memory integrity etc) causes a loss of performance for what at best is a negligable gain in security on a system not containing sensitive information so I've disabled all such features. On my work machine/networks I administer they're all turned on!

  • 3 weeks later...

Even with the Moment 3 update and all, it's still not fixed.

Wake up Microsoft!? Or does this have more impact than expected on how Windows and its security management/Windows Security behaves in W11?
Or maybe with next week's Patch Tuesday it'll be fixed?

  • Like 1
  • Sad 1
On 05/06/2023 at 10:28, kiddingguy said:

Even with the Moment 3 update and all, it's still not fixed.

Wake up Microsoft!? Or does this have more impact than expected on how Windows and its security management/Windows Security behaves in W11?
Or maybe with next week's Patch Tuesday it'll be fixed?

Maybe they really do fix things based on throwing darts while wearing a blindfold???😵

  • 1 month later...
On 06/07/2023 at 10:31, hellowalkman said:

It looks like it's solved. I think from server-side, because I haven't installed the Patch Tuesday updates not yet [doing it now].

On 06/07/2023 at 08:21, kiddingguy said:

It looks like it's solved. I think from server-side, because I haven't installed the Patch Tuesday updates not yet [doing it now].

It would have come in as a Defender update, not a patch Tuesday update.

On 06/07/2023 at 19:51, adrynalyne said:

It would have come in as a Defender update, not a patch Tuesday update.

OK. Anyways, seems like it's solved. For now 🤞

  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Google are hyprocrites for signing this. They have been pulling the same dirty tactics as Microsoft, only they do it on Android and ChromeOS.
    • In some countries the law has forced Microsoft to display a menu on a fresh install of Windows which asks which web browser you want and it will install that browser. This doesn't add any bloat to Windows. It simply an additional step when setting up a new PC.
    • Chrome is also a first party browser on Android and ChromeOS. And on those systems, Google is pulling the same dirty tactics as Microsoft does on Windows.
    • Unofficial script lets you install unreleased Windows 11 features without Microsoft Account by Sayan Sen Microsoft has been steadily evolving the Windows Insider Program over the years, introducing new channels and testing paths that allow enthusiasts to experience upcoming and yet-to-be-released Windows features (some interesting hidden ones too) before they reach the public. However, one long-standing requirement has remained largely unchanged as users are generally expected to enroll in the Program and with a Microsoft account. That's where a third-party tool called "OfflineInsiderEnroll" can help. OfflineInsiderEnroll is said to be a lightweight script that enables access to Windows Insider Program builds on systems that are not signed in with a Microsoft account. Essentially the tool configures the necessary Insider settings locally and hence allows users to select and switch between available preview channels while continuing to receive builds through the normal Windows Update channel. If you are wondering how it manages to do so, it is made possible by a Registry value known as TestFlags. When configured to"0x20", Windows stops communicating with Microsoft's online Insider enrollment services thus preventing locally configured Insider settings from being overwritten. This allows the script to apply its own channel configuration directly through the Registry as Windows Update does not verify whether a device has been officially enrolled in the Insider Program or not. Previously the utility has had already supported the traditional Insider branches including Dev, Beta, and Release Preview. However following Microsoft’s recent restructuring of its preview channels, the script has now been updated. The latest OfflineInsiderEnroll version, 2.6.6, adds support for the newly introduced Insider channel lineup. As such, users can now choose from several Experimental channels in addition to Beta and Release Preview options. The update also retains tools for refreshing the Insider cache, resetting Insider settings, and completely stopping Insider enrollment when needed. Keep in mind though that will need elevated privileges when running the script (run as Admin). You can get the latest version of OfflineInsiderEnroll from this page on its official GitHub repo.
    • The "Classic" Outlook has done that for a few years as well. The option to even change that is really hidden away too... It really shouldn't be hard to respect user defaults. Sadly we are the product now, not Outlook. To change in the Classic Outlook: File > Options > Advanced > change "Open hyperlinks from Outlook in"
  • Recent Achievements

    • Week One Done
      Dr Jared Dental Studio earned a badge
      Week One Done
    • Week One Done
      RG INVESTMENT GROUP earned a badge
      Week One Done
    • Very Popular
      The Norwegian Drone Pilot earned a badge
      Very Popular
    • Very Popular
      s0nic69 earned a badge
      Very Popular
    • Collaborator
      Asgardi earned a badge
      Collaborator
  • Popular Contributors

    1. 1
      +primortal
      472
    2. 2
      PsYcHoKiLLa
      250
    3. 3
      Skyfrog
      79
    4. 4
      FloatingFatMan
      67
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!