Overview
Windows LAPS (Local Administrator Password Solution) is a cloud-based solution that helps organizations manage the passwords of local administrator accounts on Windows devices that are enrolled in Microsoft Intune. Windows LAPS stores the passwords of local administrator accounts in Entra ID, and it provides administrators with a secure way to view, reset, and rotate these passwords.
You can learn more about Windows LAPS below:
Get started with Windows LAPS and Entra ID
Requirements
To use Windows LAPS, you need the following:
- Windows 10/11 Pro, EDU, and Enterprise: April 11, 2023 Update
- A Microsoft Intune subscription.
- Windows 10 or later devices that are enrolled in Intune.
- Entra ID Premium P1 or P2 licenses.
- Enable Windows LAPS in Entra ID (Use Windows Local Administrator Password Solution (LAPS) with Entra ID).
Benefits
Windows LAPS provides the following benefits:
- Centralized management of local administrator passwords.
- Improved security of Windows devices.
- Easy to use and deploy.
Steps
To enable Windows LAPS on Intune, you need to do the following:
- In the Intune Admin Center, go to Devices > Configuration profiles > Create profile.
- Select the Windows 10 and later platform.
- In the Profile type list, select Custom.
- In the Settings section, expand Windows LAPS.
- Select the Enabled check box.
- In the Local Administrator Account section, configure the following settings:
- Minimum password length
- Maximum password age
- Password complexity requirements
- Password history
- Click Create.
Once you have enabled Windows LAPS, you can view, reset, and rotate the passwords of local administrator accounts from the Intune Admin Center.
Things to be aware of
When using Windows LAPS, there are a few things to be aware of:
- Windows LAPS does not store the actual passwords of local administrator accounts in AAD. Instead, it stores a secure hash of these passwords.
- Windows LAPS is not a replacement for strong security practices. You should still use strong passwords for local administrator accounts and other accounts on your Windows devices.
- Windows LAPS is not a silver bullet. It is a tool that can help you to improve the security of your Windows devices, but it is not a guarantee that your devices will be secure.
If you are looking for a way to improve the security of your organization's Windows devices, then Windows LAPS is a great option. It is easy to use, deploy, and manage, and it can help you to centralize the management of local administrator passwords.