Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » AWS/Azure/OpenShift » Configure Windows LAPS Management with Microsoft Intune
  • image 64
    Windows Local Account Authorization and Access Control Windows
  • speedtest
    How to set up a self-hosted speed test server on Ubuntu Linux Linux
  • DevOps
    Create an App Service Plan with Continuous Deployment to deploy a .NET Application from GitHub AWS/Azure/OpenShift
  • web application architecture main
    Request timed out and Destination Host Unreachable, Transit Failed, General Failure Windows
  • Disable automatic updates
    Turn off Automatic Updates in Windows via Windows Registry and Group Policy Windows
  • screenshot 2020 04 22 at 23.28.23
    Remove saved RDP connections in Windows Windows
  • cisco switches 2
    How to disable Spanning-Tree Globally Network | Monitoring
  • Featured image new
    How to find out who restarted Windows Server Windows

Configure Windows LAPS Management with Microsoft Intune

Posted on 29/04/202324/02/2025 Imoh Etuk By Imoh Etuk No Comments on Configure Windows LAPS Management with Microsoft Intune
Microsoft-LAPS

In this post, I will show you how to Configure Windows LAPS Management with Microsoft Intune. Windows LAPS management with Intune is simple and straightforward. You can also modify Windows 11 Taskbar via Intune and GPO. There are a lot you can do with Intune such as managing Windows Defender Antivirus Through Microsoft Endpoint Manager Admin Dashboard and Intune. On April 11, 2023, Microsoft announced that new LAPS capabilities were coming directly to your devices.

The LAPS comes with new security updates. It is compatible with Windows editions: Windows 11 Pro, EDU, and Enterprise, Windows 10 Pro, EDU, and Enterprise, Windows Server 2022 and Windows Server Core 2022, and Windows Server 2019.

With LAPs, IT Administrators can encrypt and protect local administrator credentials using the Windows Local Administrator Password Solution (Windows LAPS), a feature of Windows. This includes backing up the passwords to Azure Active Directory or Active Directory and rotating them automatically. Below is a video on how LAPS works.

Using Microsoft Intune, you may set up Windows LAPS on your Windows workstations. See this related post to learn what ADK, MDT, Microsoft Endpoint Configuration Manager (SCCM), Intune, Autopilot, and WSUS is all about.

What is LAPS, and why do we need it?

The “Local Administrator Password Solution” (LAPS) allows domain-joined workstations to manage local account passwords. Only authorized users are able to access or request the reset of passwords since they are stored in Active Directory (AD) and secured by ACL.

Password management can become a difficult problem when users must log on to devices without domain credentials (such as local admin). The possibility of a Pass-the-Hash (PtH) credential replay attack is significantly increased in such environments.

Using a common local account with the same password on each machine in a domain is a problem that LAPS addresses. Please see how to configure Windows LAPS in Active Directory.

This problem is fixed by LAPS by assigning a unique, random password to each machine in the domain for the common local administrator account. By utilizing the solution, domain administrators can identify which individuals, such as help desk administrators, are permitted to access passwords.

Please see how to Install Windows Admin Center on Windows 10 and Windows 11, and how to schedule and run updates via Windows Admin Center.

Configuring LAPS with Microsoft Intune

To configure LAPS with Intune, follow the below steps:

Step 1: Create an Account Protection Policy. Visit the Microsoft Intune Portal and navigate to Endpoint Security > Account Protection> + Create Policy

creating-account-policy
Account Protection Creation Page

In the Platform field, select Windows 10 or later and in the Profile, select Local admin password solution (Windows LAPS) and click on Create.

create-profile-section
Creating Profile Policy

Specify a unique name for your new policy and description (optional) and then click Next

specifying-policy-name
Specifying the Policy Name

On the configuration page, in the Backup Directory field, select Backup the password to Azure AD only.

policy-config-page-1
Configuring the Policy

You can learn more about the above configuration settings in the official documentation maintained by Microsoft.

Skip the scope tags page and move directly to the Assignments tab. When you are there, assign the new policy to a device group, or all devices.

select-group
Assigning New Policy to All Devices

In the Review + Create pane, confirm the policy meets your requirements before creating it.

review-create-page
Review and Create

Accessing the Local Admin Password of a Device

There are a number of options for an administrator to view the local administrator password. These include PowerShell, Microsoft Entra, and the Intune Admin Portal. Here, we are just going to view it through Microsoft Entra Admin Center.

Please see how to use GitHub as Source Provider to AWS CodePipeline, how to add and remove Multiple Virtual Desktops in Windows 10 Multitasking, How to configure Pleasant Password MsSQL SSO, how to create a Mapped Drive via GPO Preferences and how to delete Apps from Launchpad on Mac

Viewing Using Microsoft Entra

Visit the Microsoft Entra admin portal. Check through the left pane under Azure Active Directory, click on Devices, then click All Devices.

List-of-Devices
All Devices

Now click on the device of your choice and then click on Show local administrative password to view it.

show-local-admin-passwd
Viewing Local Administrative Password from Intune Dashboard

In this post, you have learned how to Configure Windows LAPS Management with Microsoft Intune. Microsoft Intune. Microsoft Intune is a Microsoft cloud-based unified endpoint management service for both corporate and BYOD devices.

It extends some of the “on-premises” functionality of Microsoft Endpoint Configuration Manager to the Microsoft Azure cloud.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
AWS/Azure/OpenShift, Security | Vulnerability Scans and Assessment, Windows Tags:microsoft, Microsoft Windows, Windows 10, Windows 11

Post navigation

Previous Post: How to use GitHub as Source Provider for AWS CodePipeline
Next Post: Various ways to restart an AWS EC2 instance

Related Posts

  • Feature image Install.wim file
    How To Get Install.WIM From Windows 10 Installation File Windows
  • Complete Guide on TestRail as a Test Management Tool   banner
    Complete Guide on TestRail as a Test Management Tool Security | Vulnerability Scans and Assessment
  • banner
    How to hide Folders and Files from Search Results in Windows Windows
  • image 2
    How to Fix Microsoft Edge Not Responding Windows
  • MSSQL Always On Cluster on Azure
    [AZURE] Procedure for creating an MSSQL Always On Cluster on Azure AWS/Azure/OpenShift
  • blog banner 1
    Reset and reinstall Windows 10 from the cloud and how to recover your Windows 10 when you cannot boot to Windows Windows

More Related Articles

Feature image Install.wim file How To Get Install.WIM From Windows 10 Installation File Windows
Complete Guide on TestRail as a Test Management Tool   banner Complete Guide on TestRail as a Test Management Tool Security | Vulnerability Scans and Assessment
banner How to hide Folders and Files from Search Results in Windows Windows
image 2 How to Fix Microsoft Edge Not Responding Windows
MSSQL Always On Cluster on Azure [AZURE] Procedure for creating an MSSQL Always On Cluster on Azure AWS/Azure/OpenShift
blog banner 1 Reset and reinstall Windows 10 from the cloud and how to recover your Windows 10 when you cannot boot to Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • image 64
    Windows Local Account Authorization and Access Control Windows
  • speedtest
    How to set up a self-hosted speed test server on Ubuntu Linux Linux
  • DevOps
    Create an App Service Plan with Continuous Deployment to deploy a .NET Application from GitHub AWS/Azure/OpenShift
  • web application architecture main
    Request timed out and Destination Host Unreachable, Transit Failed, General Failure Windows
  • Disable automatic updates
    Turn off Automatic Updates in Windows via Windows Registry and Group Policy Windows
  • screenshot 2020 04 22 at 23.28.23
    Remove saved RDP connections in Windows Windows
  • cisco switches 2
    How to disable Spanning-Tree Globally Network | Monitoring
  • Featured image new
    How to find out who restarted Windows Server Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,825 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.