DPAPI is a core Windows component designed to protect sensitive data by encrypting it using the user's logon credentials or the system's identity. It eliminates the need for applications to manage their own encryption keys.

Data Protected by DPAPI


Key Hierarchy and Storage

DPAPI relies on a multi-layered key hierarchy to ensure that data remains inaccessible even if the physical disk is stolen.

Master Keys (The Root of Trust)

Master Keys are 64-byte random values used to protect the "Session Keys" that actually encrypt the data. They are renewed every 90 days by default.


The Local Security Authority (LSA)

The LSASS (lsass.exe) process manages DPAPI keys in memory. When a user logs in, LSA decrypts the Master Key and keeps it in memory so that the user doesn't have to provide their password every time an application requests data decryption.

Mock-up of LSA Memory (Readable Format):

LSA DPAPI Cache