Microsoft announced that the newest build of Windows 11 released to Insiders in the Canary channel will now come with Local Security Authority (LSA protection) protection as a default feature.
See also: Outdated Windows UAC bypass allows phishing campaigns

A Canary Build is an experimental version of Windows that has not yet been fully tested or stabilized for public use. These builds are released to Windows Insiders—Windows users who have chosen to become “test animals” to test new features before they are made available to the public. This way, Microsoft can identify any bugs or glitches associated with its latest software updates and ensure that they don’t impact the user experience when the new features are released to the public.
Implementing LSA protection is vital to ensuring the security and confidentiality of your data, as it prevents malicious actors from injecting unauthorized code into the system's process memory or leaking sensitive information.
Microsoft's Windows 11 security application protects credentials by preventing any unauthorized drivers or add-ons from entering the local security authority.
Simply put, LSA protection acts as a sentinel, ensuring that only authorized entities have access to critical information required for user authentication and system security
Although Windows 11's enhanced security feature is promising, it will only be enabled after successfully completing a system check to ensure compatibility.
See also: Microsoft is testing a redesigned Windows 11 audio mixer

“To ensure that our upgrade is fully compatible with LSA protection, we will conduct a thorough review over an extended period of time.” With no known incompatibilities, the Microsoft team, consisting of Amanda Langowski and Brandon LeBlanc, expressed their intention to enable LSA protection.
Windows Insiders can quickly determine whether LSA protection is enabled on their systems by going to the Device Security > Core Isolation in the Windows Security app.
To check if any LSA add-ons and drivers are blocked, they can use the Windows Event Log. They should open Event Viewer and look for events with IDs 3033 or 3063 in the Microsoft-Windows-Codeintegrity/Operational box . This should give them all the information they need!
In February 2022, Microsoft announced its intention to enable an “Attack Surface Reduction” security rule for Microsoft Defender by default. This feature is designed to block any attempts to steal Windows credentials from the Local Security Authority Subsystem Service (LSASS) process.
Windows 11 Insiders on the Canary Channel are now receiving a new Insider Preview Build 25314, which will drastically enhance security by disabling the Remote Mailslot as a default setting.
See also: Notepad gets tabs in Windows 11
Today, Microsoft is excited to release a new preview build of Windows 11 for the recently launched Dev Channel. This nifty update contains several innovative features, including an improved toast notification button for copying two-factor authentication codes, access keys in File Explorer , and a new VPN.
