LSASS - Local and Domain
LSA and LSASS: local and domain authentication
The Local Security Authority (LSA) is the Windows security subsystem. The Local
Security Authority Subsystem Service, lsass.exe, is the protected system
process that implements core LSA functions in user mode. It enforces local
security policy, coordinates authentication packages, creates access tokens,
and maintains security context for active sessions.
Main components
| Component | Role |
|---|---|
lsasrv.dll | LSA server and security-package manager; Negotiate selects Kerberos or NTLM as appropriate. |
msv1_0.dll | NTLM authentication package and local SAM validation path. |
| Kerberos security package | Kerberos client authentication and ticket handling. |
netlogon.dll | Maintains the computer's secure channel to a domain controller and supports domain authentication. This is separate from Schannel. |
samsrv.dll | Manages local accounts and locally stored account policy. |
secur32.dll | User-mode Security Support Provider Interface entry points used by applications. |
kdcsvc.dll | KDC service on a domain controller; issues Kerberos tickets. |
ntdsa.dll | Active Directory Domain Services database and directory-service functionality on a domain controller. |
What can exist in session memory
Depending on the sign-in method, protocol, Windows version, and policy, LSASS
can hold password-derived material, NT hashes, Kerberos TGTs or service tickets,
and other reusable authentication state for active sessions. It is inaccurate
to assume every session contains plaintext credentials.
With Credential Guard enabled, supported Kerberos, NTLM, and Credential Manager
secrets are isolated with virtualization-based security in LSAIso.exe. LSASS
uses RPC to request operations from the isolated process. Credential Guard has
documented exclusions, so its presence does not mean every credential type is
protected.
Defensive validation
- Confirm whether LSA protection and Credential Guard are enabled on the host.
- Alert on unauthorized process access to LSASS and unexpected dump creation.
- Limit debug rights and local administrative membership.
- Use protected forensic procedures for any approved memory acquisition.
Operational dumping commands belong in the authorized RTO shelf. This note
keeps the platform model and the security boundaries needed to interpret host
evidence.