lsass.exe

Local Security Authority Subsystem Service

System Critical Security
CPU Usage
0-5%
Memory
10-30 MB
Location
System32
Publisher
Microsoft

Quick Answer

lsass.exe is safe and critical. It's the Local Security Authority Subsystem Service that handles user logins, password changes, and enforces security policies. Often targeted by malware.

Is it a Virus?
✔ SAFE (if legitimate)
Frequently impersonated by malware
Warning
Critical System Process
Terminating it causes immediate reboot
Can I Disable?
✘ NEVER - System Critical
Required for Windows security

What is lsass.exe?

lsass.exe (Local Security Authority Subsystem Service) is one of the most critical Windows processes. It handles authentication, password changes, access token creation, and enforces local security policy. Every time you log in, lsass.exe verifies your credentials.

LSASS is so critical that ending it causes Windows to immediately reboot within 60 seconds. It runs with SYSTEM privileges and has deep integration with Windows security. Unfortunately, it's also one of the most commonly targeted processes by malware and credential-stealing attacks.

Main Functions

Is lsass.exe Safe?

Yes, the legitimate lsass.exe is completely safe when it's the authentic Microsoft process.

How to Verify Legitimacy

  1. File Location: MUST be C:\Windows\System32\lsass.exe (NEVER System32 without Windows prefix!)
  2. Digital Signature: Microsoft Windows Publisher
  3. User Account: SYSTEM only
  4. Single Instance: Only ONE lsass.exe should ever run
  5. Parent Process: wininit.exe

Warning: CRITICAL: lsass.exe in any location except C:\Windows\System32 is MALWARE. Multiple lsass.exe processes = malware. File in C:\Windows\System32 (without Windows parent folder) is fake. Malware often uses similar names like 'lssas.exe', 'lsaas.exe', or 'lsass32.exe'. Terminate and scan immediately.

High CPU or Memory Usage

High resource usage by lsass.exe can occur under certain conditions.

Common Causes

Solutions

  1. Verify Location - Confirm file is in C:\Windows\System32\lsass.exe
  2. Check Digital Signature - Must be signed by Microsoft
  3. Scan for Malware - Use multiple antivirus tools if suspicious
  4. Monitor with Process Explorer - Check parent process is wininit.exe
  5. Enable Credential Guard - Windows 10 Enterprise: protects lsass memory
  6. Update Windows - Security patches protect against lsass exploits