iShield OpenSC Minidriver
Windows OS/Patch: Windows 11 23H2 & 24H2
LSA prevents the Swissbit OpenSC Minidriver from loading, and that minidriver is required for managing PIV smart card options on an iShield, adding/removing certificates & private keys, changing the smart card PIN.
Below error is shown:
The Microsoft Local Security Authority (LSA) was introduced as an optional protection mechanism in Windows 8.1 to defend against malware running on user’s computer. Starting with Windows 11 2023 H2 & 2024 H2 Microsoft turned LSA on by default.
Swissbit is currently working on obtaining official certification to operate on Windows when Local Security Authority (LSA) is enabled. If your Windows machine has already been updated to Windows 11 version 24H2 or 23H2, follow the steps below to disable LSA and restore the functionality of the OpenSC Minidriver
To disable LSA using Registry Editor
- Press Win + R, type regedit, and press Enter.
- Navigate to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
- Look for a key named RunAsPPL.
- If it exists, double-click it and set Value data to 0.
- If it does not exist, create a DWORD (32-bit) Value named RunAsPPL, then set it to 0 as follows: "RunAsPPL"=dword:00000000
- Look for a key named RunAsPPL.
- Restart your computer.
To disable LSA using Group Policy
- Open the Local Group Policy Editor by entering gpedit.msc.
- Expand Computer Configuration > Administrative Templates > System > Local Security Authority.
- Open the Configure LSASS to run as a protected process policy.
- Set the policy to Disable.
- Restart the machine
Related Articles
RSA Announces the Release of iShield Key Manager 1.13.1 26Number of Views What is the purpose of the nic_sshd and nic_sftp accounts? 38Number of Views RSA WTD Silvertail - varz for silvertap or other remote service won't load...remote silvertap machine(s) 44Number of Views RSA SecurID Passage 3.5.1 unable to update roaming profile for Active Directory Domain User 7Number of Views Issue loading Server Nodes tab after RSA Identity Governance & Lifecycle 7.1.0 installation on WebSphere 9.x clustered env… 31Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x