If every PC shares one local administrator password, one leaked credential opens them all. Windows LAPS gives each device its own password, rotates it on a schedule and, with Intune, backs it up to Microsoft Entra ID. In this post I'll walk through the tenant switch, the Intune profile, password retrieval and rotation, and how to confirm it's working.
Prerequisites#
- Windows: Windows LAPS is built into Windows 11. Windows 10 is only covered while it still receives updates, for example through Extended Security Updates.
- Join type: Microsoft Entra joined or Microsoft Entra hybrid joined, and enrolled in Intune. Microsoft Entra registered devices aren't supported.
- Licensing: Intune Plan 1. LAPS itself works with Microsoft Entra ID Free; custom roles for password access need Microsoft Entra ID P1 or P2.
- Roles: at least Cloud Device Administrator to enable the tenant setting, and Intune Security baselines permissions (included in the built-in Endpoint Security Manager role) to create the policy.
- An account to manage: LAPS manages an existing account. Leave the name blank to use the built-in Administrator, or create your custom account first.
Step-by-step#
Step 1: Allow LAPS in Microsoft Entra ID#
Microsoft Entra ID rejects LAPS passwords until you enable the feature, and forgetting this step is the most common reason backups fail. In the Microsoft Entra admin center, go to Entra ID › Devices › Overview › Device settings, set Enable Local Administrator Password Solution (LAPS) to Yes, and select Save.
Step 2: Create the Intune profile#
In the Microsoft Intune admin center, go to Endpoint security › Account protection › Create Policy, choose platform Windows and profile Local admin password solution (Windows LAPS). The settings that matter most:
| Setting | What it controls | Default / range |
|---|---|---|
| Backup Directory | Where the password is stored. Pick the Microsoft Entra ID option; it must suit the device's join type. | Disabled if not set, so nothing is backed up |
| Password Age Days | Maximum age before automatic rotation | 30; 7 to 365 when backing up to Microsoft Entra ID |
| Administrator Account Name | The account to manage. Blank means the built-in Administrator, found by its well-known RID even if renamed. | Blank |
| Password Complexity | Character sets, or passphrases (values 6 to 8, Windows 11 24H2 and later) | Upper case, lower case, numbers and special characters |
| Password Length | Number of characters | 14; 8 to 64 |
| Post Authentication Actions | What happens after someone uses the password and the delay expires | Reset the password and sign out the managed account |
| Post Authentication Reset Delay | Hours to wait before those actions; 0 turns them off | 24; 0 to 24 |
Note: Windows 11 24H2 and later also offer automatic account management, which can create and manage a dedicated account for you instead of relying on one you created.
Step 3: Assign it to device groups#
Assign the profile to device groups and make sure each device receives only one LAPS policy. User-group targeting changes the configuration whenever a different person signs in, and two policies with different values conflict: the device keeps its previous values or, if both arrive together, applies neither.
Verify#
On the device#
LAPS processes its policy every hour. To skip the wait, run this in an elevated PowerShell window:
Invoke-LapsPolicyProcessing
Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 15 |
Format-Table TimeCreated, Id, LevelDisplayName -AutoSizeIn Event Viewer it's Applications and Services Logs › Microsoft › Windows › LAPS › Operational. A healthy cycle looks like this:
| Event ID | Meaning |
|---|---|
| 10003 | Policy processing started |
| 10022 | Current policy; expect policy source CSP and the Microsoft Entra backup directory |
| 10029 | New password stored in Microsoft Entra ID |
| 10020 | Local account updated with the new password |
| 10004 / 10005 | Cycle succeeded / failed; read the events in between |
In the portals#
In Intune, open Devices › All devices, select the device and, under Monitor, choose Local admin password. You'll see the account name, its SID, the password behind Show, and the last and next rotation times in UTC. In Microsoft Entra ID, Entra ID › Devices › Overview › Local administrator password recovery lists every LAPS-enabled device.
Reading the password requires microsoft.directory/deviceLocalCredentials/password/read. Cloud Device Administrator and Intune Administrator include it; Helpdesk Administrator, Security Administrator and Security Reader see metadata only. Each retrieval is audited as Recover device local administrator password.
With PowerShell#
Get-LapsAADPassword ships with Windows and wraps the Microsoft Graph PowerShell SDK. You need the Microsoft.Graph module and an app registration with Device.Read.All plus DeviceLocalCredential.Read.All (or DeviceLocalCredential.ReadBasic.All for metadata only):
Connect-MgGraph -TenantId '<tenant-id>' -ClientId '<app-client-id>'
Get-LapsAADPassword -DeviceIds 'PC-0042' -IncludePasswords -AsPlainTextTips & gotchas#
- Manual rotation: the Rotate local admin password device action (in the device's … menu) needs the Intune permissions Managed devices: Read, Organization: Read and Remote tasks: Rotate Local Admin Password. It works one device at a time, Microsoft Entra joined devices must be online, it restarts the Password Age Days clock, and it fails on devices that never backed up a password. On the device,
Reset-LapsPassworddoes the same; heavy use can be throttled. - The CSP wins: once LAPS settings arrive through the CSP, Group Policy and legacy LAPS configurations are ignored.
- Deleting the device in Microsoft Entra ID deletes its stored password, with no way to recover it.
- Event 10013 means the configured account doesn't exist. 10025, 10028, 10032 and 10059 point at Microsoft Entra ID: confirm the tenant setting is on, the device isn't disabled or deleted,
dsregcmd /statusis clean, andenterpriseregistration.windows.netis reachable. - Event 20000 means the CSP rejected the policy because the device didn't appear joined, which can happen during Autopilot pre-provisioning until the user phase completes.
- Protect retrieval with Conditional Access, for example by requiring MFA for the built-in roles that can read passwords.