In default mode, access to LSASS is not blocked, but an event is sent to the Endpoint Security server detection.
After installation, run Process Guard in default detection mode.
Go to the Process Guard home page to review the applications accessing LSASS.
Decide, which processes need access to LSASS, and add them to the Process Guard Policy Exclusions.
Continue to monitor for new events to establish a reasonable baseline, and then enable blocking mode and alerting capability.
Note
If you enable the alerting functionality too early, it can cause an overload of alerts for review and acknowledgment.