- Local time
- 11:42 AM
- Posts
- 192
- OS
- Windows 11 Intel i5 10400 HD630 graphics chip
I never saw any of the following stuff in Win11 21h2.
Each boot up/restart I get the following list of LSA warnings in Event Viewer ID 6155.
LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
PackageName: negoexts
PackageName: kerberos
PackageName: msv1_0
PackageName: tspkg
PackageName: pku2u
PackageName: cloudap
PackageName: wdigest
PackageName: schannel
PackageName: sfapm
I have read through 'Configuring Additional LSA Protection' serveral times
and the article indicates its for Windows Server 2022, 2016, 2019.
I am using Windows Home 22h2, not a server. Windows home also does not have GPO.
Under section on the article 'how to disable LSA protection' -
I have looked at registry Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa.
but.. I don't have 'RunAsAPPL dword. So I assume by not having the setting
that LSA should not be running/starting, why all the warnings.
To best of my knowledge I don't have Keberos, negoexts, and all the others listed above.
Machine seems to be running just fine but would like to get rid of warnings.
I have also looked thru the Event Viewer 'windows system and application' logs for
Event ID 12 indicating that LSA was started, there are no Event ID 12's.
So if its not loading the above items and no Event ID I assume its not running/starting
at all, so why again the logs.
Thanks in advance, sorry for the large post
Each boot up/restart I get the following list of LSA warnings in Event Viewer ID 6155.
LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
PackageName: negoexts
PackageName: kerberos
PackageName: msv1_0
PackageName: tspkg
PackageName: pku2u
PackageName: cloudap
PackageName: wdigest
PackageName: schannel
PackageName: sfapm
I have read through 'Configuring Additional LSA Protection' serveral times
and the article indicates its for Windows Server 2022, 2016, 2019.
I am using Windows Home 22h2, not a server. Windows home also does not have GPO.
Under section on the article 'how to disable LSA protection' -
I have looked at registry Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa.
but.. I don't have 'RunAsAPPL dword. So I assume by not having the setting
that LSA should not be running/starting, why all the warnings.
To best of my knowledge I don't have Keberos, negoexts, and all the others listed above.
Machine seems to be running just fine but would like to get rid of warnings.
I have also looked thru the Event Viewer 'windows system and application' logs for
Event ID 12 indicating that LSA was started, there are no Event ID 12's.
So if its not loading the above items and no Event ID I assume its not running/starting
at all, so why again the logs.
Thanks in advance, sorry for the large post
My Computer
System One
-
- OS
- Windows 11 Intel i5 10400 HD630 graphics chip
- Computer type
- PC/Desktop
- Manufacturer/Model
- HP
- CPU
- i5-10400
- Memory
- 12 gb
- Graphics Card(s)
- HD630 chipset
- Monitor(s) Displays
- LG 24inch
- Hard Drives
- SSD, external usb drive 1tb for files/backups
- Keyboard
- wireless Logi
- Mouse
- ms 4000 wireless mouse
- Internet Speed
- 10meg
- Browser
- Firefox
- Antivirus
- Defender
- Other Info
- Win11 Home 24h2 26100.3915 4/25/2025