Information
This policy setting controls whether the Local Security Authority Subservice Service (LSASS) runs in protected mode and also has the option to lock in protected mode with Unified Extensible Firmware Interface (UEFI). The Local Security Authority (LSA), which includes the LSASS process, validates users for local and remote sign-ins and enforces local security policies.
The recommended state for this setting is: Enabled with UEFI lock. LSA will run as protected process and this configuration is UEFI locked
Provides added security for the credentials that LSA stores and manages. Enabling this setting with UEFI Lock prevents the setting from being changed remotely.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled with UEFI lock...
Local Security Authority\Configure Lsa Protected Process
Impact:
Once this setting has been applied (Enabled), removing the group policy setting (set to Not Configured) will not reverse the impact. In order to reverse the impact, you must explicitly configure this setting to Disabled and follow
Microsoft's documentation on disabling the UEFI Lock
.