CNG Key Isolation (KeyIso) Service on Windows Server 2012


What is the "CNG Key Isolation (KeyIso)" system service on Windows Server 2012? Can I disable "CNG Key Isolation"?



"CNG Key Isolation (KeyIso)" is a Windows Server 2012 service that provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements. KeyIso (CNG Key Isolation)

CNG stands for "Cryptography Application Programming Interface - Next Generation". A "Key" is a cryptographic token, for example, one generated from a wireless networking passphrase. "Isolation" is to do with Public Key Cryptography. Inside the operating system, public keys have to be kept separate from private keys and that is what the service is for.

Detailed information on "CNG Key Isolation" service:

Service name: KeyIso
Display name: CNG Key Isolation
Execution command: 
   Remote Procedure Call (RPC)
   Extensible Authentication Protocol

"CNG Key Isolation" service is provided by the lsass.exe program, see "lsass.exe Executable Program on Windows Server 2012" for details.

Disabling "CNG Key Isolation" service will cause issues on running Windows 2012 Server with wireless connections.


