Support Forum: Get Support for Patch My PC Products and Services

Commercial Products: Support for Our Enterprise Product for Microsoft ConfigMgr and Intune => Commercial/Paid Products: Support and General Questions (ConfigMgr and Intune) => Topic started by: Thadders on April 02, 2025, 01:00:42 AM

Title: Has someone else had a similar experience
Post by: Thadders on April 02, 2025, 01:00:42 AM
Hello,

We are using PMPC alongside Intune and the Microsoft Defender Stack. Recently we switched on Attack Surface Reduction (ASR) Rules in Intune. They were designed for improving the security Posture on devices. On reviewing the Block Events we noticed the "PatchMyPC-ScriptRunner.exe" file was blocked by one Rule: "Block credential stealing from the Windows security authority subsystem."
Why is the file blocked for that reason (It needs to try to access the Windows local security subsystem LSASS). Has someone else  had a similar experience and did you notice an Impact in App Distribution?

I appreciate any Feedback.
Title: Re: Has someone else had a similar experience
Post by: Liviu (Patch My PC) on April 02, 2025, 06:43:57 AM
Hello Thadders,

LSASS is used when displaying the "Conflicting Processes" deferral notification to end users, to allow them to postpone the installation if needed.
Are you using the "Manage conflicting processes (https://patchmypc.com/manage-conflicting-processes-when-updating-third-party-applications)" right-click option>
Using that functionality is how the notification is displayed to the logged on user while Intune does the installation of the software in the SYSTEM context.

Please note that Microsoft recommends whitelisting the IMECache folder from AV scans to prevent win32 app installation issues such as this one.
https://patchmypc.com/recommended-antivirus-exclusions (https://patchmypc.com/recommended-antivirus-exclusions)