IntuneHow-to

Deploying Windows LAPS with Intune and backing up passwords to Microsoft Entra ID

Set up Windows LAPS end to end: enable it in Microsoft Entra ID, build the Intune account protection profile, retrieve and rotate passwords, and check the LAPS event log.

If every PC shares one local administrator password, one leaked credential opens them all. Windows LAPS gives each device its own password, rotates it on a schedule and, with Intune, backs it up to Microsoft Entra ID. In this post I'll walk through the tenant switch, the Intune profile, password retrieval and rotation, and how to confirm it's working.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (3 steps: Allow LAPS in Microsoft Entra ID; Create the Intune profile; Assign it to device groups). 3. Verify. 4. Tips & gotchas. Toolbox: Event ID 10013, Event ID 20000, Get-LapsAADPassword, Reset-LapsPassword, dsregcmd /status.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Allow LAPS in MicrosoftEntra ID2Create the Intune profile3Assign it to devicegroupsTOOLBOXEvent ID 10013Event ID 20000Get-LapsAADPasswordReset-LapsPassworddsregcmd /statusHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (3 steps: Allow LAPS in Microsoft Entra ID; Create the Intune profile; Assign it to device groups). 3. Verify. 4. Tips & gotchas. Toolbox: Event ID 10013, Event ID 20000, Get-LapsAADPassword, Reset-LapsPassword, dsregcmd /status.1Prerequisites2Step-by-step1Allow LAPS in Microsoft Entra ID2Create the Intune profile3Assign it to device groups3Verify4Tips & gotchasTOOLBOXEvent ID 10013Event ID 20000Get-LapsAADPasswordReset-LapsPassworddsregcmd /status
At a glance: how this guide is organised · 3 steps · 5 key settings and tools

Prerequisites#

  • Windows: Windows LAPS is built into Windows 11. Windows 10 is only covered while it still receives updates, for example through Extended Security Updates.
  • Join type: Microsoft Entra joined or Microsoft Entra hybrid joined, and enrolled in Intune. Microsoft Entra registered devices aren't supported.
  • Licensing: Intune Plan 1. LAPS itself works with Microsoft Entra ID Free; custom roles for password access need Microsoft Entra ID P1 or P2.
  • Roles: at least Cloud Device Administrator to enable the tenant setting, and Intune Security baselines permissions (included in the built-in Endpoint Security Manager role) to create the policy.
  • An account to manage: LAPS manages an existing account. Leave the name blank to use the built-in Administrator, or create your custom account first.

Step-by-step#

Step 1: Allow LAPS in Microsoft Entra ID#

Microsoft Entra ID rejects LAPS passwords until you enable the feature, and forgetting this step is the most common reason backups fail. In the Microsoft Entra admin center, go to Entra ID › Devices › Overview › Device settings, set Enable Local Administrator Password Solution (LAPS) to Yes, and select Save.

Step 2: Create the Intune profile#

In the Microsoft Intune admin center, go to Endpoint security › Account protection › Create Policy, choose platform Windows and profile Local admin password solution (Windows LAPS). The settings that matter most:

SettingWhat it controlsDefault / range
Backup DirectoryWhere the password is stored. Pick the Microsoft Entra ID option; it must suit the device's join type.Disabled if not set, so nothing is backed up
Password Age DaysMaximum age before automatic rotation30; 7 to 365 when backing up to Microsoft Entra ID
Administrator Account NameThe account to manage. Blank means the built-in Administrator, found by its well-known RID even if renamed.Blank
Password ComplexityCharacter sets, or passphrases (values 6 to 8, Windows 11 24H2 and later)Upper case, lower case, numbers and special characters
Password LengthNumber of characters14; 8 to 64
Post Authentication ActionsWhat happens after someone uses the password and the delay expiresReset the password and sign out the managed account
Post Authentication Reset DelayHours to wait before those actions; 0 turns them off24; 0 to 24

Note: Windows 11 24H2 and later also offer automatic account management, which can create and manage a dedicated account for you instead of relying on one you created.

Step 3: Assign it to device groups#

Assign the profile to device groups and make sure each device receives only one LAPS policy. User-group targeting changes the configuration whenever a different person signs in, and two policies with different values conflict: the device keeps its previous values or, if both arrive together, applies neither.

Verify#

On the device#

LAPS processes its policy every hour. To skip the wait, run this in an elevated PowerShell window:

PowerShell
Invoke-LapsPolicyProcessing
Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 15 |
    Format-Table TimeCreated, Id, LevelDisplayName -AutoSize

In Event Viewer it's Applications and Services Logs › Microsoft › Windows › LAPS › Operational. A healthy cycle looks like this:

Event IDMeaning
10003Policy processing started
10022Current policy; expect policy source CSP and the Microsoft Entra backup directory
10029New password stored in Microsoft Entra ID
10020Local account updated with the new password
10004 / 10005Cycle succeeded / failed; read the events in between

In the portals#

In Intune, open Devices › All devices, select the device and, under Monitor, choose Local admin password. You'll see the account name, its SID, the password behind Show, and the last and next rotation times in UTC. In Microsoft Entra ID, Entra ID › Devices › Overview › Local administrator password recovery lists every LAPS-enabled device.

Reading the password requires microsoft.directory/deviceLocalCredentials/password/read. Cloud Device Administrator and Intune Administrator include it; Helpdesk Administrator, Security Administrator and Security Reader see metadata only. Each retrieval is audited as Recover device local administrator password.

With PowerShell#

Get-LapsAADPassword ships with Windows and wraps the Microsoft Graph PowerShell SDK. You need the Microsoft.Graph module and an app registration with Device.Read.All plus DeviceLocalCredential.Read.All (or DeviceLocalCredential.ReadBasic.All for metadata only):

PowerShell
Connect-MgGraph -TenantId '<tenant-id>' -ClientId '<app-client-id>'
Get-LapsAADPassword -DeviceIds 'PC-0042' -IncludePasswords -AsPlainText

Tips & gotchas#

  • Manual rotation: the Rotate local admin password device action (in the device's … menu) needs the Intune permissions Managed devices: Read, Organization: Read and Remote tasks: Rotate Local Admin Password. It works one device at a time, Microsoft Entra joined devices must be online, it restarts the Password Age Days clock, and it fails on devices that never backed up a password. On the device, Reset-LapsPassword does the same; heavy use can be throttled.
  • The CSP wins: once LAPS settings arrive through the CSP, Group Policy and legacy LAPS configurations are ignored.
  • Deleting the device in Microsoft Entra ID deletes its stored password, with no way to recover it.
  • Event 10013 means the configured account doesn't exist. 10025, 10028, 10032 and 10059 point at Microsoft Entra ID: confirm the tenant setting is on, the device isn't disabled or deleted, dsregcmd /status is clean, and enterpriseregistration.windows.net is reachable.
  • Event 20000 means the CSP rejected the policy because the device didn't appear joined, which can happen during Autopilot pre-provisioning until the user phase completes.
  • Protect retrieval with Conditional Access, for example by requiring MFA for the built-in roles that can read passwords.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)