This blog will explain how to setup local administrator password solution. This guide is for creating, configuring, and deploying LAPS, Microsoft’s Local Administrator Password Solution.
Microsoft LAPS can be utilized to manage local administrator passwords on your domain-joined devices. LAPS (Local Administrator Password Solution) creates a unique and random password for each device client in your network and stores it in the Active Directory.
Microsoft Local Administrator Password Solution resolves this issue by establishing a unique, complex password for the local administrator account in all domain-joined devices. This password, set by Microsoft LAPS, will automatically change the password policy. The new passwords will be saved in the Active Directory, and authorized administrators can retrieve them from the Active Directory server when necessary.
Install Microsoft LAPS Software on Management Computers
The LAPS software should be installed on both management computers and client computers. The management features will be used to set up, configure, and manage LAPS.
You can install the LAPS management software on the domain controller or another domain-joined computer, such as Windows 10/11.
Download the local administrator password solution download LAPS from Microsoft.
Select a language and click on download.
data:image/s3,"s3://crabby-images/5c6ad/5c6ad201ed08153cc124ce6db7128df46bd47599" alt="Download local administrator password solution"
Choose the download you want and click on download.
data:image/s3,"s3://crabby-images/34506/34506d872f0e060c72f7bfa544a67f3db08f299f" alt="Download laps.x64.msi"
Double-click the file LAPS.x64.msi to begin the installation.
data:image/s3,"s3://crabby-images/2a571/2a571ed292cfb675f695a7bea806793e7ca755fc" alt="LAPSx64 installer file"
Click on the setup wizard screen.
data:image/s3,"s3://crabby-images/f17bf/f17bf60d554dca8b06c24a61d58200af71d6b192" alt="Local administrator password solution setup"
Accept the license agreement and click next.
data:image/s3,"s3://crabby-images/329ff/329ffcb5a69da5b8ec3202fa92bf4ac1a8deca56" alt="LAPS end user license agreement"
Click on Management Tools, select “Entire feature will be installed on local hard drive,” and select the next option.
data:image/s3,"s3://crabby-images/5dd39/5dd39ad6bb423069bad878d8ed7e83bdf4b28ead" alt="LAPS custom setup"
Click Install.
data:image/s3,"s3://crabby-images/14962/14962ac5df20e903cff56f45150fb496475f9a85" alt="Install Microsoft LAPS"
When the installation is complete, click Finish.
data:image/s3,"s3://crabby-images/ee6a5/ee6a566d418ef42d3a63bec7d9eb038ce10c9dc8" alt="Completed the LAPS setup wizard"
Open LAPS UI.
data:image/s3,"s3://crabby-images/22fa0/22fa078d0aa9f6561e58acbdd74a2b22bbdd3b6f" alt="LAPS UI"
Create Security Groups for Local Administrator Password Solution
I have already created an OU named Organization and inside two more OU (Workstations,
Organization).
To create security groups, right-click on security groups (OU).
Select new and then group.
data:image/s3,"s3://crabby-images/6fa2d/6fa2d61089c009862edc1722efaed648908da811" alt="Active directory users and computers"
Type a security group name (LAPSAdmins) and click ok.
data:image/s3,"s3://crabby-images/27a1a/27a1a78489baba369b65ce0f8a0bc8759a47b376" alt="Create security group"
To assign security group permission, right-click on the security group and choose properties.
data:image/s3,"s3://crabby-images/1c0f0/1c0f0bbc22e10072a97f26f1bbd5064098af7f3c" alt="Active directory users and computers"
Select the Members tab and click on the Add button.
data:image/s3,"s3://crabby-images/dd08f/dd08f02d8c667d2c59da37ce91dd072244593d11" alt="Security group properties members tab"
Type domain admins and click ok.
data:image/s3,"s3://crabby-images/172cd/172cddac31b90c1915ad14021bac652c9938519c" alt="Enter the object name to"
Verify security group permissions and click ok.
data:image/s3,"s3://crabby-images/38d15/38d15bc7ee2d57f3e9e210a0455104a641d7fe85" alt="Security group properties mermbers"
The LAPS software installation for the management computer is complete. The next step is to return to the management system to complete the LAPS setup.
In the above sample, “Workstations” is the OU I created for the PC components.
Assign Permissions to the Group for Password Access
In my demo environment, I possess a security group called “LAPSAdmins”. I require users in this group to verify the local administrators’ passwords. Before we assign permissions, let’s see who had the privilege to view the passwords by default.
Extend the Active Directory Schema
You must log in with an account member of the Scheme admins group in Active Directory.
Run the two commands below:
Import-module AdmPwd.PS
Update-AdmPwdADSchema
data:image/s3,"s3://crabby-images/92815/928157aea1f7939f1b7918be6d7511c7e98704fd" alt="Update-AdmPwdADSchema command"
Set Permissions in the Active Directory
With the PowerShell window still open (e.g., Import the AdmPwd.ps again), we will set the required permissions for LAPS. We will need to provide the SELF built-in account on the computer with write access so it can update the password in the Active Directory. We must also permit the administrators to read the stored LAPS password. Type the following command.
Set-AdmPwdComputerSelfPermission -OrgUnit Workstations
data:image/s3,"s3://crabby-images/a7db1/a7db1c2dd079d3c9fcf58d40b753de584c9c93cf" alt="Set-AdmPwdComputerSelfPermission -OrgUnit"
Set-AdmPwdReadPasswordPermission -Identity Workstations -AllowedPrincipals "LAPSAdmins"
data:image/s3,"s3://crabby-images/61509/61509c336720c3046efc04f7814d4f6984da3c50" alt="Setup local administrator password solution"
Setting up the LAPS GPO
Go to:
\Srv2022sysvolxpertstec.localscripts
Srv2022 is an active directory server name.
Create a new folder.
data:image/s3,"s3://crabby-images/eaddf/eaddf09e62d8127fafc9311de19697860b92bc06" alt="create new folder"
Type a name LAPS
data:image/s3,"s3://crabby-images/7c879/7c879b6e954c1d1a2da859154803f5a72da81b26" alt="active directory script folder"
in the LAPS folder, and paste the LAPSx64 exe file.
data:image/s3,"s3://crabby-images/f94e8/f94e8023bfb7f08f57361e4ac1d9477cbf54694e" alt="Active directory script folder LAPS"
copy the path.
data:image/s3,"s3://crabby-images/730f1/730f165bd8713f5977049bf72a8189083b529c5a" alt="Active directory script folder LAPS folder"
Configure Group Policy Settings for LAPS
The final configuration process is to create a group policy for the LAPS settings.
Open the group policy management console.
data:image/s3,"s3://crabby-images/bd9d9/bd9d94647da2cc845cea2ead1ca2049ca83bd4c5" alt="Search group policy management"
Create a new GPO on the OU that has your computers.
Right-click on group policy objects and choose new.
data:image/s3,"s3://crabby-images/1d1c9/1d1c95539c9d83ebc5aa7124be3c96e75685486e" alt="Group policy management"
Give the GPO a name (LAPS) and select ok.
data:image/s3,"s3://crabby-images/adecf/adecf445b5cf5aee8ccf3cf4445f1e5be0b60331" alt="Create a new policy"
Edit the GPO
data:image/s3,"s3://crabby-images/305c0/305c0605c43ac0708713e71bcde0bd83dcdfa9c6" alt="Edit group policy"
Go to:
Computer configurationpoliciessoftware installation
Right-click, choose new, and then package.
data:image/s3,"s3://crabby-images/1e3da/1e3da977d0bcc9a841b8d156954306192acf1b9a" alt="Group policy management editor"
Go to:
\active directory serversysvolxpertstec.localscriptsLAPS
Select the LAPSx64.exe file and select open.
data:image/s3,"s3://crabby-images/7f592/7f59236ef069ae7ef98dfabaa8c778cdae90c2fb" alt="Active directory server scripts location"
Click ok
data:image/s3,"s3://crabby-images/33a3f/33a3fa111515c71ba96907bf1e6e1df61daf095d" alt="Select deployment method assigned"
Now, you can see the local administrator password solutions that have been assigned.
data:image/s3,"s3://crabby-images/53646/53646356de636a4e007d7a4f7aa101a2dc224a3f" alt="Group policy software installation"
Configure Windows Local Administrator Password Solution
Browse to the following policy settings:
Computer ConfigurationPoliciesAdministrative TemplatesLAPS
Open enable local admin password management.
data:image/s3,"s3://crabby-images/dc569/dc569aa762e5eede7374c3f57bccd8138ed8b0b8" alt="Group policy management editor"
Click on Enable and then OK.
data:image/s3,"s3://crabby-images/03df3/03df33d9873758935ac436c212eff08243f8d525" alt="enable local admin password management"
Click on the Policy Password Settings.
Select Enable. Then select the password complexity settings and click OK.
data:image/s3,"s3://crabby-images/1e85d/1e85db2616bdb43ee05d551622161ab2d6875c92" alt="Setup local administrator passwords solution"
Enable “do not allow password expiration time longer than required by policy”.
data:image/s3,"s3://crabby-images/97538/9753832110f594a5f30894b699e12fe2e170364b" alt="Se tup local administrator password solution"
If you have a custom local administrator account that you want to manage, you can enable the administrator account name to be managed.
Note: Even if you changed the built-in admin account, you do not need to configure this policy. This policy is only applicable for custom local admin accounts.
Link an Existing GPO
Right-click on workstations and choose link an existing GPO.
data:image/s3,"s3://crabby-images/e2296/e22967a786d1323b904bebe50813be4e51bb494d" alt="Link an existing GOP"
Select LAPS and click ok.
data:image/s3,"s3://crabby-images/650c2/650c203ffa8de4bcf3d334fee250e6a9821cf3eb" alt="Assing group policy"
That completes the configuration process of Microsoft Laps.
How to View the Local Administrator Password with LAPS
Open the LAPS UI program on your management computer.
Enter a computer name and click the search.
No password is found.
data:image/s3,"s3://crabby-images/198cf/198cf91af4f7d1abc355b9da694fc8efc44324a5" alt="LAPS UI"
Login to your client’s computer and update the group policy.
Open the command prompt and type the following command.
Gpupdate /force
You need to restart your client’s computer.
data:image/s3,"s3://crabby-images/1bdd2/1bdd223abd9c5e973d4f277c1a4e6cc489de2a03" alt="Gpupdate /force command"
After restarting, update the group policy again.
data:image/s3,"s3://crabby-images/ff92a/ff92a12918fa9c95e73b24b06458ca6e79d9ab83" alt="Gpupdate /force updating policy"
Go back to your active directory computer and click on search again.
data:image/s3,"s3://crabby-images/72a19/72a1970bcafdf15b45eecea8826333ab3771761f" alt="Local administrator passwords solutions"
Now, you can select expiration time.
data:image/s3,"s3://crabby-images/bdcc4/bdcc407e3c5c1d33861ae1427e42407c376535c6" alt="Select expiration time LAPS"
Above, you can see the local administrator password for Windows 11 and when the password expires.
Using PowerShell.
Get-AdmPwdPassword Windows11
Or right-click on the Windows11 client computer and select properties.
data:image/s3,"s3://crabby-images/ad702/ad702e84a4ecf4f9dae38c080bbeb4847936a26b" alt="Active directory users and computers"
You can also view the password in Active Directory by opening the computer and selecting the Attribute Editor.
data:image/s3,"s3://crabby-images/5e12e/5e12e4e9d73e6df4b5cbff461fdcc94b49940e26" alt="LAPS Attribute editor"