Event banner
Default hardening in Windows 11, version 22H2
Event Ended
Monday, Oct 24, 2022, 07:30 AM PDTEvent details
Explore the ins and outs of two security features enabled by default in Windows 11, version 22H2: Windows Defender Credential Guard and LSA protection. Explore the criteria for enablement, security benefits, and management capabilities plus get details on our new security baseline.
This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, RSVP for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
Heather_Poulsen
Updated Dec 27, 2024
52 Comments
Sort By
- Heather_Poulsen
Community Manager
For easy reference, here is a list of the links from this session:
- Heather_Poulsen
Community Manager
How did we do on our Technical Takeoff Day 1 sessions? Please take this 2-minute survey and let us know your thoughts on this event.
- Mika_Seitsonen_SCopper Contributor
My Win 11 22H2 laptop seems to have ten 6155 events during each startup, e.g.
Log Name: System
Source: LsaSrv
Date: 24/10/2022 12.48.30
Event ID: 6155
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: NNN
Description:
LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.PackageName: kerberos
Same warnings also for negoexts, kerberos, msv1_0 (twice), tspkg, pku2u, cloudap, wdigest, schannel and sfapm
What I should do to stop these events from occurring?
- jirenugo
Microsoft
This is a known bug and will be fixed in a future update. There is nothing wrong with the packages.
- JEngel05Brass ContributorIs there an Intune Settings Catalog option for enabling LSA protection for Windows 10 systems?
- Matthew_Palko
Microsoft
LSA Protection currently does not have an Intune Settings Catalog option.
- Frank_MaxwitatCopper ContributorI was hoping to get some information on Smart App Control. Will there be any Takeoff session where this is covered?
- sassankaraiCopper ContributorThe concept of Smart App is very interesting. Currently once set to on or off the settings cant be modified further and will require a system reinstall. After turning it on using a test system I noticed several applications being limited to partial functionality only. I would recommend leaving it in default evaluation mode for the time being.
- Frank_MaxwitatCopper ContributorI wonder for how long it will be under my control. The documentation says: "If you are a good candidate for Smart App Control, then it will automatically be turned on. If not, it'll be turned off.". That sounds scarry to me since I don't see a management option - or did I miss something?
- DaneaGalbraithIron ContributorWith MDM do you have filter recommendations to send them out to specific machines?
- JEngel05Brass ContributorWill the MDM policies for LSA and Credential Guard tattoo?
- Greg_C_GilbertIron ContributorBe very careful with the UEFI lock options. If you use those, you must physically touch the PCs to turn off the setting. It cannot be done remotely.
- Heather_Poulsen
Community Manager
We’re happy you joined us at the Microsoft Technical Takeoff! Whether you are attending one session or many, please take this 2-minute survey and let us know your thoughts on this event.
- DaneaGalbraithIron ContributorTo use this with MDM do you need both of those CSP?
- jirenugo
Microsoft
You need only the respective CSP(Device Guard for Credential Guard and Local Security Authority for LSA protection) if you want to change the default setting.
- Greg_C_GilbertIron ContributorIs there a recommended method for creating filters in Intune or collections in ConfigMgr that can contain only PCs that include all the hardware requirements for enabling HVCI? I got bit several years ago where we enabled HVCI with UEFI lock on many PCs that didn't support it and it caused severe performance issues.
- jirenugo
Microsoft
We don't have any recommendations right now. Thanks for the feedback! We will look into documenting the hardware requirements or providing a scripted mechanism to identify devices that can support VBS features. This is a good place to start Virtualization-based Security (VBS) | Microsoft Learn
- Greg_C_GilbertIron ContributorFollow-up. Is there a way for companies to implement these settings in a scripted way that does the same checks that a fresh install of W11 22H2 does? It would be great if the product team could provide that.