Hi,
The SDprop process is the responsible to protect the ACLs of protected account by disabling the inheriting and applying the ACL template of AdminSDHolder on protected objects. This Process run automatically evevry 60 min by minute.
To know if a account is protected or not by this process , you can check the value of the attribute AdminCount.
To get more details about this process , I invite you to read this article:
appendix-c--protected-accounts-and-groups-in-active-directory
Please don't forget to mark this reply as answer if it help you to fix your issue