iShield OpenSC Minidriver
Windows OS/Patch: Windows 11 23H2 & 24H2
LSA prevents the Swissbit OpenSC Minidriver from loading, and that minidriver is required for managing PIV smart card options on an iShield, adding/removing certificates & private keys, changing the smart card PIN.
Below error is shown:
The Microsoft Local Security Authority (LSA) was introduced as an optional protection mechanism in Windows 8.1 to defend against malware running on user’s computer. Starting with Windows 11 2023 H2 & 2024 H2 Microsoft turned LSA on by default.
Swissbit is currently working on obtaining official certification to operate on Windows when Local Security Authority (LSA) is enabled. If your Windows machine has already been updated to Windows 11 version 24H2 or 23H2, follow the steps below to disable LSA and restore the functionality of the OpenSC Minidriver
To disable LSA using Registry Editor
- Press Win + R, type regedit, and press Enter.
- Navigate to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
- Look for a key named RunAsPPL.
- If it exists, double-click it and set Value data to 0.
- If it does not exist, create a DWORD (32-bit) Value named RunAsPPL, then set it to 0 as follows: "RunAsPPL"=dword:00000000
- Look for a key named RunAsPPL.
- Restart your computer.
To disable LSA using Group Policy
- Open the Local Group Policy Editor by entering gpedit.msc.
- Expand Computer Configuration > Administrative Templates > System > Local Security Authority.
- Open the Configure LSASS to run as a protected process policy.
- Set the policy to Disable.
- Restart the machine
Related Articles
RSA WTD Silvertail - varz for silvertap or other remote service won't load...remote silvertap machine(s) 44Number of Views SAML 2.0 Requirements for Service Providers - Supported RequestedAuthnContext Examples 14Number of Views RSA Announces the Release of iShield Key Manager 1.13.1 26Number of Views Error: Error 'Socket Closed exception in RSA Federated Identity Manager (FIM) 2.5' 6Number of Views Roadmunk - SAML SSO Agent Configuration - SecurID Access Implementation Guide 1Number of Views
Trending Articles
RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) Troubleshooting RSA SecurID Access Application Portal unsuccessful logon message due to a bad identity source bind RSA Release Notes: Cloud Access Service and RSA Authenticators