Windows LAPS: Local Administrator Password Management
Windows LAPS (Local Administrator Password Solution) gives Windows administrators a controlled way to rotate and recover local administrator credentials across managed devices. It is useful to IT and security teams that need to prevent a shared local password from becoming a path between compromised computers. This explainer covers how the built-in Windows feature stores credentials in Active Directory Domain Services (AD DS) or Microsoft Entra ID, how to deploy it, and how to restrict password access.
Why Windows LAPS Is Being Discussed
Windows LAPS brings password rotation and directory-backed recovery into supported Windows versions, replacing the need to deploy the older Microsoft LAPS client on current systems. It addresses a recurring endpoint-security problem: local administrator accounts can exist outside an organization’s central user sign-in flow, so their passwords need a separate lifecycle. Knowing how the policy, backup directory, and access controls fit together is important when organizations update security baselines or move devices between domain and cloud management.
What Is Windows LAPS?
Windows LAPS is a Windows feature that manages the password of a local administrator account. A policy controls the account, password characteristics, rotation interval, and backup destination. The managed device generates and changes the password, then stores it in either AD DS or Microsoft Entra ID. Administrators with the appropriate delegated permissions can retrieve the password when responding to a support or recovery need.
The Windows LAPS overview from Microsoft describes the feature and its supported backup directories. Windows LAPS is included in supported Windows releases, so it is not simply a new name for the separately installed legacy Microsoft LAPS client. The exact capabilities available depend on the device’s Windows version and the policy configuration.
The Problem Windows LAPS Solves
Organizations often use a local administrator account for device recovery, offline maintenance, or software troubleshooting. If many computers share the same password, an attacker who obtains that credential from one device may be able to use it on other devices. That turns a local compromise into a lateral-movement opportunity.
Manually setting different passwords is not a durable fix. Administrators need to know which password belongs to which computer, rotate it after use, make it available during an outage, and keep a record of who accessed it. Those steps become difficult to coordinate across large device fleets.
Windows LAPS automates the rotation and backup parts of this process. It does not replace least-privilege design, endpoint protection, or domain identity controls. Instead, it gives local administrator credentials a managed lifecycle and allows organizations to control who can recover them.
How Windows LAPS Works
The device applies a policy, selects the local account it should manage, and creates a password that meets the configured requirements. At the policy-defined interval, it rotates the password and writes the new value and associated metadata to the configured directory. An authorized operator requests the credential from the directory when it is needed.
The device and directory must be configured for the same backup destination. AD DS and Entra ID have different policy and permission models:
| Feature | AD DS backup | Microsoft Entra ID backup |
|---|---|---|
| Typical device relationship | Domain-joined or hybrid-managed Windows devices | Microsoft Entra-joined Windows devices |
| Policy delivery | Group Policy or supported mobile device management policy | Mobile device management, commonly Microsoft Intune |
| Password storage | Attributes on the computer object in AD DS | Device password data in the Entra directory |
| Password retrieval | Delegated AD DS permissions and Windows LAPS tools | Entra role-based permissions and supported admin experiences |
| Directory preparation | Extend the AD DS schema and delegate computer and reader permissions | No AD DS schema extension; configure the Entra backup policy |
The exact supported combinations depend on Windows version, join state, management channel, and current Microsoft requirements. Microsoft’s Windows LAPS architecture documentation explains the components and the differences between backup scenarios.
For AD DS, the managed device updates its computer object. LDAP is the directory protocol used for operations against AD DS; RFC 4511 specifies LDAP protocol behavior, not the Windows LAPS password policy or schema. Password access should be delegated through directory permissions rather than granted broadly to every directory administrator.
Key Components and Variants
The managed local account. Windows LAPS normally targets the built-in local Administrator account. A policy can instead identify another local account, which must already exist. Account selection matters: a typo or account that is absent can prevent the intended password from being managed. Avoid treating a rotated password as a substitute for disabling unnecessary accounts or restricting local administrator membership.
Policy and backup directory. Settings include the backup directory, password length and complexity, password age, and (where supported) post-authentication actions. Group Policy and MDM can deliver Windows LAPS settings. Microsoft’s policy settings reference documents individual settings and their behavior.
Directory permissions and recovery. AD DS deployments require preparation and carefully delegated rights. Entra deployments use Entra permissions and role-based access. In either case, password readers are privileged: restrict the role to a small support group, use an approved recovery process, and audit access according to organizational policy.
Windows LAPS and legacy Microsoft LAPS. Windows LAPS is the in-box Windows implementation. Legacy Microsoft LAPS is a separate, older client and management approach. Their policies, tools, and update behavior are not interchangeable. Plan migration deliberately: check OS support, policy precedence, directory preparation, and management tooling before removing an older deployment.
Real-World Use Cases
- Help-desk recovery: An authorized technician retrieves a workstation’s current local administrator password to repair a device that cannot use its normal sign-in or remote management path.
- Reducing lateral movement: Unique, regularly rotated passwords prevent one recovered local credential from serving as a shared password across a fleet.
- Server operations: A server team can recover a local account using a defined approval path without relying on one static password shared among operators.
- Domain controller recovery: In supported AD DS scenarios, Windows LAPS can manage the Directory Services Restore Mode (DSRM) account, giving administrators a controlled way to recover that separate maintenance credential.
- Cloud-managed endpoints: Entra-joined devices can back up their local administrator passwords to Entra ID instead of requiring an on-premises AD DS computer object.
In all of these cases, LAPS is one layer in endpoint security. It does not make a device trustworthy after compromise, remove the need to monitor privileged access, or replace a separate emergency-access plan.
Getting Started with Windows LAPS
Start by identifying Windows versions, device join state, management channel, and the account to be managed. Choose one backup directory for each device population, then test the policy on a small organizational unit or pilot group. Follow Microsoft’s current Windows LAPS deployment guidance, since supported versions and prerequisites can change.
For AD DS, a directory administrator with the required schema rights prepares the forest once. Then delegate computers’ ability to update their own LAPS attributes on the target OU, and grant password readers only to a designated support group:
# Run once per AD DS forest with the required schema permissions.
Update-LapsADSchema
# Delegate the managed computers' write permissions on their OU.
Set-LapsADComputerSelfPermission `
-Identity 'OU=Workstations,DC=contoso,DC=com'
# Delegate password reading to a narrowly scoped support group.
Set-LapsADReadPasswordPermission `
-Identity 'OU=Workstations,DC=contoso,DC=com' `
-AllowedPrincipals 'CONTOSO\LAPS Password Readers'
Replace the example OU and group with values from the environment. Use a test OU first and review permissions before broad deployment. Schema preparation is a privileged, forest-level operation; OU delegation should be performed by an administrator authorized to change those objects.
In Group Policy, configure the Windows LAPS settings under Computer Configuration > Administrative Templates > System > LAPS. Select AD DS as the backup directory for a domain deployment, and set the password and rotation requirements to the organization’s policy. For an Entra deployment, configure the Windows LAPS policy through a supported MDM channel, such as Intune, and select Entra ID as the backup directory. Avoid configuring competing policies for the same device.
After the device receives policy, refresh computer policy when using Group Policy and review the local Windows LAPS operational log:
gpupdate /target:computer /force
Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 20 |
Select-Object TimeCreated, Id, LevelDisplayName, Message
For an AD DS device, an authorized reader can verify the directory record and its expiration without printing the password:
(Get-LapsADPassword -Identity 'WS-042').ExpirationTimestamp
If the record is missing or stale, check the operational log, device policy, account selection, directory permissions, and connectivity before expanding the rollout. Do not put retrieved passwords in tickets, scripts, or shared command output. For MDM-managed devices, also verify policy assignment and device check-in in the management console. See the guide to configuring Windows devices with Intune for broader enrollment and policy-management context.
Common Misconceptions
“LAPS manages every administrator password.” It manages a configured local Windows account, not domain administrator credentials, user passwords, or every service credential. Inventory local accounts and choose the intended account explicitly when defaults are not appropriate.
“Storing the password in a directory makes it safe for every administrator to read.” Directory backup does not define who should have access. Use narrowly delegated permissions or Entra roles, follow an auditable retrieval process, and periodically review membership and access.
“Password rotation alone prevents endpoint compromise.” LAPS reduces reuse and limits the usefulness of a recovered password across devices. It does not stop malware, protect an already controlled endpoint, or replace patching, endpoint detection, application control, and least privilege.
Related Articles
- Active Directory Domain Services System Design
- Windows Security Baseline Automation
- Configuring Windows Devices with Intune
- Windows Security Hardening Guide
Changelog
- 2026-10-03: First publication.

