TDAD - Block LSASS features Support for Windows 11 24H2 and later
search cancel

TDAD - Block LSASS features Support for Windows 11 24H2 and later

book

Article ID: 411523

calendar_today

Updated On:

Products

Endpoint Security Complete

Issue/Introduction

The feature "Block LSASS memory attacks"  and "Enable deception account in LSASS" as per : Configuring the Threat Defense for AD policy is not supported for devices installed with Windows 11, version 24H2 update and Windows 2025 or later.

Environment

Endpoint Security Complete.

Windows 24H2 and later.

Windows Server 2025.

 

Cause

LSASS is provided by Microsoft in the  Windows OS. We had a method to hook into that using TDAD. But in Windows 11 24H2 patch, Microsoft took that ability out of the OS. It is not something we can restore in our product.

Resolution

We are leaving the feature available for a reasonable amount of time as long as customers are still using it. But Windows 10 goes EOL in less than a month, and earlier versions of Windows 11 will go EOL too. At that point we will remove the feature from the agent, the policy, and the documentation.

If customer wants to use the feature they can reach out to Microsoft to restore the function as it was before.