Skip to content
arrow_back
search
E8-RA-ML3.5 bolt ASD Essential Eight

Local Security Authority protection functionality is enabled

Ensure LSA protection is on to prevent malware from stealing credentials.

record_voice_over

Plain language

Local Security Authority (LSA) protection helps keep your computer safe by stopping sneaky programs from stealing important information like passwords. Without this protection, malware could grab your credentials and gain access to your systems, leading to data breaches or unauthorised access.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Local Security Authority protection functionality is enabled.
bolt ASD Essential Eight E8-RA-ML3.5
priority_high

Why it matters

Without LSA protection, attackers can dump LSASS to steal credential material, enabling account takeover and unauthorised access.

settings

Operational notes

Enforce LSA protection via GPO/Intune, verify it remains enabled after patching, and monitor Windows events for attempts to disable RunAsPPL.

Mapping detail

Mapping

Direction

Controls