How to fix error 6155 LSA Package is not signed as expected

Norman Shilling 0 Reputation points
2024-01-10T15:31:02.1766667+00:00

I am seeing an error 6155 in the Windows event log that says LSA Package is not signed as expected. Can someone explain what this means and how to fix it?

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,381 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Karlie Weng 14,801 Reputation points Microsoft Vendor
    2024-01-11T06:56:07.9833333+00:00

    Hello
    Norman Shilling
    , I came across many users have encountered this issue. I have summarized the following fixes from the internet, and I hope they help.

    • Uninstall Recent Updates Some users reported that they get rid of this error by uninstalling the recent update
    • Enable LSA Protection via Registry Editor Here’s how to do it:
    1. Press Win + S to evoke the search bar.
    2. Type registry editor and hit Enter.
    3. Go to the following location: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
    4. Set the value of the registry key to: "RunAsPPL"=dword:00000001 to configure the feature with a UEFI variable. "RunAsPPL"=dword:00000002 to configure the feature without a UEFI variable (only on Windows 11, 22H2). “RunAsPPLBoot value”= dword:00000002
    5. Restart the computer. If the registry key RunAsPPL does not exist create it as a New DWORD (32-bit) Value and set the Hexadecimal value to 00000002.
    • Turn off Credential Guard LSA package is not signed as expected indicates that Windows Defender Credential Guard might show unexpected behavior. Therefore, you can consider disabling this feature using the following method. Navigate to local computer policy >computer configuration >administrative templates>system User's image

    From this thread, one user commented that we can ignore those, because they are related to password-based SSO.   To stop the Events, we can open Regedit Navigate to key
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System{199fe037-2b82-40a9-82ac-e1d46c792b99} And Set Enabled to 0 Clear all events and reboot.   Reference: Configuring Additional LSA Protection I hope this helps! Please let me know if you need any further assistance. Kind Regards,
    Karlie Weng

    ---If the Answer is helpful, please click "Accept Answer" and upvote it.