If LSA Protection had been enabled, that post-exploitation step would have failed. The attacker would have seen an "Access Denied" error instead of a domain admin hash.
If not, you just found a five-minute fix that could save your domain. Have you run into compatibility issues after enabling LSA Protection? Let me know in the comments below. local security authority protection
Locking the Vault: Why You Need to Enable Local Security Authority Protection If LSA Protection had been enabled, that post-exploitation