Manually turning this on from my personal computer only sets the RunAsPPL key to 2. So, either they forgot to generate the RunAsPPLBoot key when enabling LSA Protection or whatever checks Defenders health was programed to check for the presence of both keys. What's sad is that this issue was known for months in Dev and Canary builds. Microsoft needs to do a better job of listening to the community and update their documentation if they are going to make changes.
Nothing mentioned in the MS site about RunAsPPLBoot, that document is pretty old and not updated either. 🤷♂️🤐
MS never answered my questions about these security updates either. They just started rolling them out to all users without any clarification😝🤣🤬
Configuring Additional LSA Protection | Microsoft Learn
One web site added this note at the bottom of the article:
Update 1: Microsoft has started rolling out a fix, but it’s taking longer than usual to reflect on all systems worldwide as users continue to run into the problem.
Windows 11 incorrectly warns Local Security Authority protection is off (windowslatest.com)