Yes, it seems it is all about CET. This would also explain why my laptop, an Intel® Core™ i5-1135G7, can support this function.
I will try to contact Intel.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
OS Name Microsoft Windows 11 Pro
Version 10.0.22621 Build 22621
Processor 11th Gen Intel(R) Core(TM) i7-11700 @ 2.50GHz, 2496 Mhz, 8 Core(s), 16 Logical Processor(s)
On this computer (desktop) i get no option for Kernel-mode Hardware-enforced Stack Protection, although all requirements are met.
On my laptop with an identical Windows installation, the option is present.
Before this, i had the "Local Security Authority protection is off with persistent restart" error:
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#3048msgdesc
So far i have tried rebooting the computer and resetting the security app. Please see the attachment for further information.
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Yes, it seems it is all about CET. This would also explain why my laptop, an Intel® Core™ i5-1135G7, can support this function.
I will try to contact Intel.
Hi Benjamin,
I am Dave, I will help you with this.
Lat month Microsoft released an Update that caused an LSA error to appear in Windows Security, this week they released an update to patch that LSA bug and that has introduced a new bug (Kernel-mode Hardware-enforced Stack Protection) that you are now seeing.
it is unclear what is causing this bug, some indicate it is an incompatible driver or an anti-cheat game engine causing the bug, but either way we now need to wait for Microsoft to resolve this bug, there is currently no fix for this.
TPM is activated, as can be clearly seen in the fourth screenshot from above.
Hi Benjamin,
I cannot see in your screenshots, is TPM enabled in BIOS?
If it is, and if you do not have your drive encrypted with Bitlocker or any other method, boot into BOS and select the option to reset TPM keys, save that setting and then check if the option then appears in Windows security.
If that does not solve this, it is possible your processor does not support that functionality, I know it is available on the Intel 11th gen Tigerlake processors, but I cannot find whether your processor falls into that category.
I am aware of this bug, however in my case the entire option is not present (see screenshot).
In all the other cases i have seen the option is present, like so:
https://www.reddit.com/r/Windows11/comments/12r2cdl/how_can_i_fix_this_issue/
How can the entire option be missing?