Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » AWS/Azure/OpenShift » Configure Windows LAPS Management with Microsoft Intune

Configure Windows LAPS Management with Microsoft Intune

Posted on 29/04/202324/02/2025 Imoh Etuk By Imoh Etuk No Comments on Configure Windows LAPS Management with Microsoft Intune
Microsoft-LAPS

In this post, I will show you how to Configure Windows LAPS Management with Microsoft Intune. Windows LAPS management with Intune is simple and straightforward. You can also modify Windows 11 Taskbar via Intune and GPO. There are a lot you can do with Intune such as managing Windows Defender Antivirus Through Microsoft Endpoint Manager Admin Dashboard and Intune. On April 11, 2023, Microsoft announced that new LAPS capabilities were coming directly to your devices.

The LAPS comes with new security updates. It is compatible with Windows editions: Windows 11 Pro, EDU, and Enterprise, Windows 10 Pro, EDU, and Enterprise, Windows Server 2022 and Windows Server Core 2022, and Windows Server 2019.

With LAPs, IT Administrators can encrypt and protect local administrator credentials using the Windows Local Administrator Password Solution (Windows LAPS), a feature of Windows. This includes backing up the passwords to Azure Active Directory or Active Directory and rotating them automatically. Below is a video on how LAPS works.

Using Microsoft Intune, you may set up Windows LAPS on your Windows workstations. See this related post to learn what ADK, MDT, Microsoft Endpoint Configuration Manager (SCCM), Intune, Autopilot, and WSUS is all about.

What is LAPS, and why do we need it?

The “Local Administrator Password Solution” (LAPS) allows domain-joined workstations to manage local account passwords. Only authorized users are able to access or request the reset of passwords since they are stored in Active Directory (AD) and secured by ACL.

Password management can become a difficult problem when users must log on to devices without domain credentials (such as local admin). The possibility of a Pass-the-Hash (PtH) credential replay attack is significantly increased in such environments.

Using a common local account with the same password on each machine in a domain is a problem that LAPS addresses. Please see how to configure Windows LAPS in Active Directory.

This problem is fixed by LAPS by assigning a unique, random password to each machine in the domain for the common local administrator account. By utilizing the solution, domain administrators can identify which individuals, such as help desk administrators, are permitted to access passwords.

Please see how to Install Windows Admin Center on Windows 10 and Windows 11, and how to schedule and run updates via Windows Admin Center.

Configuring LAPS with Microsoft Intune

To configure LAPS with Intune, follow the below steps:

Step 1: Create an Account Protection Policy. Visit the Microsoft Intune Portal and navigate to Endpoint Security > Account Protection> + Create Policy

creating-account-policy
Account Protection Creation Page

In the Platform field, select Windows 10 or later and in the Profile, select Local admin password solution (Windows LAPS) and click on Create.

create-profile-section
Creating Profile Policy

Specify a unique name for your new policy and description (optional) and then click Next

specifying-policy-name
Specifying the Policy Name

On the configuration page, in the Backup Directory field, select Backup the password to Azure AD only.

policy-config-page-1
Configuring the Policy

You can learn more about the above configuration settings in the official documentation maintained by Microsoft.

Skip the scope tags page and move directly to the Assignments tab. When you are there, assign the new policy to a device group, or all devices.

select-group
Assigning New Policy to All Devices

In the Review + Create pane, confirm the policy meets your requirements before creating it.

review-create-page
Review and Create

Accessing the Local Admin Password of a Device

There are a number of options for an administrator to view the local administrator password. These include PowerShell, Microsoft Entra, and the Intune Admin Portal. Here, we are just going to view it through Microsoft Entra Admin Center.

Please see how to use GitHub as Source Provider to AWS CodePipeline, how to add and remove Multiple Virtual Desktops in Windows 10 Multitasking, How to configure Pleasant Password MsSQL SSO, how to create a Mapped Drive via GPO Preferences and how to delete Apps from Launchpad on Mac

Viewing Using Microsoft Entra

Visit the Microsoft Entra admin portal. Check through the left pane under Azure Active Directory, click on Devices, then click All Devices.

List-of-Devices
All Devices

Now click on the device of your choice and then click on Show local administrative password to view it.

show-local-admin-passwd
Viewing Local Administrative Password from Intune Dashboard

In this post, you have learned how to Configure Windows LAPS Management with Microsoft Intune. Microsoft Intune. Microsoft Intune is a Microsoft cloud-based unified endpoint management service for both corporate and BYOD devices.

It extends some of the “on-premises” functionality of Microsoft Endpoint Configuration Manager to the Microsoft Azure cloud.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
AWS/Azure/OpenShift, Security | Vulnerability Scans and Assessment, Windows Tags:microsoft, Microsoft Windows, Windows 10, Windows 11

Post navigation

Previous Post: How to use GitHub as Source Provider for AWS CodePipeline
Next Post: Various ways to restart an AWS EC2 instance

Related Posts

  • Featured image Some Settings are managed by your organization
    How to Fix “Some Settings Are Managed by Your Organization” Error in Windows Update Windows
  • jhgfx
    How to make Cortana use your default web browser such as Google Chrome Windows
  • MAP virtual disk error
    Install Workstation Pro 17: Fix failed to initialise library for mounting and unmounting virtual disks Virtualization
  • How to Manage Azure Virtual Machines with Windows Admin Center and Serial Console​
    Manage Azure Virtual Machine with Windows Admin Center and Serial Console AWS/Azure/OpenShift
  • How to Install Windows Admin Center on Windows 10 11​
    Install Windows Admin Center on Windows 10 and Windows 11 Windows
  • HyperV VM disk size increase
    How to Increase Disk Size in Hyper-V Virtualization

More Related Articles

Featured image Some Settings are managed by your organization How to Fix “Some Settings Are Managed by Your Organization” Error in Windows Update Windows
jhgfx How to make Cortana use your default web browser such as Google Chrome Windows
MAP virtual disk error Install Workstation Pro 17: Fix failed to initialise library for mounting and unmounting virtual disks Virtualization
How to Manage Azure Virtual Machines with Windows Admin Center and Serial Console​ Manage Azure Virtual Machine with Windows Admin Center and Serial Console AWS/Azure/OpenShift
How to Install Windows Admin Center on Windows 10 11​ Install Windows Admin Center on Windows 10 and Windows 11 Windows
HyperV VM disk size increase How to Increase Disk Size in Hyper-V Virtualization

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Exchange
    Update Global Address List: Fixing the “Not Recognized” Error Microsoft Exchange/Office/365
  • How to determine Active Directory Site Name
    How to determine Active Directory Site Name Network | Monitoring
  • Fix 0x800f0831 Windows Update
    Fix 0x800f0831 Error when installing Windows update Windows
  • Screenshot 2020 08 13 at 03.29.53
    Windows Modules Installer: How to deactivate TrustedInstaller in Windows Windows
  • screenshot 2020 04 06 at 04.12.00
    How to install and Configure Pleasant Reset Password Virtualization
  • system
    How to fix the system cannot find the file specified when adding LP, LIP, and FoD packages to Windows Images Windows Server
  • fix Client Certificate Mapping Authentication error
    How to fix Client Certificate Mapping Authentication error Backup
  • Windows Admin Center V2511
    How to upgrade Windows Admin Center from v2411 to v2511 Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,823 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.