This document discusses new process protection mechanisms introduced in Windows 8.1 that extend the protected process model to key non-DRM system processes. It protects processes like LSA even from Administrators, and mitigates pass-the-hash attacks. Digital signatures and code signing add another boundary of protection beyond just load/don't load. Processes can now be designated as protected or protected light, assigned a protected signer like Windows or Antimalware, and have increased restrictions on access.