Microsoft LAPS Intune Step-by-Step Guide: Complete Configuration and Deployment

Managing local administrator passwords across multiple Windows devices has always been a challenge for IT teams. This Microsoft LAPS Intune Step-by-Step guide explains how to configure, deploy, and manage Windows LAPS using Microsoft Intune. By following this guide, administrators can automate password rotation, strengthen endpoint security, and centrally manage local administrator credentials across their organisation.




What Is Microsoft LAPS?

Microsoft LAPS (Local Administrator Password Solution) is a built-in Windows security feature that automatically manages local administrator account passwords on Windows devices.

Instead of using the same administrator password across every device, Microsoft LAPS generates a unique password for each endpoint and rotates it according to your organisation's password policy.

Key benefits include:

  • Automatic password rotation
  • Unique passwords for every device
  • Secure password storage
  • Reduced risk of lateral movement
  • Centralised password management
  • Enhanced endpoint security

Why Use Microsoft LAPS with Microsoft Intune?

Microsoft Intune simplifies the deployment and management of Microsoft LAPS across enterprise environments.

Benefits include:

  • Centralised policy management
  • Cloud-based administration
  • Automatic deployment
  • Remote password retrieval
  • Easy password rotation
  • Integration with Microsoft Entra ID
  • Improved compliance and security posture

This combination eliminates the need for manual password management while helping organisations follow security best practices.


Prerequisites

Before deploying Microsoft LAPS, ensure you have the following:

  • Microsoft Intune administrator access
  • Microsoft Entra ID joined, or Hybrid Entra joined Windows devices
  • Windows 11 or supported Windows 10 version with Windows LAPS
  • Devices enrolled in Microsoft Intune
  • Appropriate administrative permissions
  • Internet connectivity for policy synchronisation

Verifying these prerequisites before deployment helps avoid common configuration issues.


Step 1: Verify Windows LAPS Support

Before creating any policies, confirm that your Windows devices support the built-in Microsoft LAPS feature.

Check:

  • Windows version
  • Device enrollment status
  • Microsoft Entra join status
  • Latest Windows updates installed

Keeping devices fully updated ensures compatibility with Microsoft LAPS features.


Step 2: Create a Microsoft LAPS Policy in Intune

Open the Microsoft Intune Admin Center.

Navigate to:

Endpoint Security → Account Protection → Create Policy

Choose:

  • Platform: Windows 10 and later
  • Profile: Local Administrator Password Solution (Windows LAPS)

Click Create.

Give your policy a meaningful name, such as:

Windows LAPS Configuration

Providing clear names makes future administration easier.


Step 3: Configure Password Settings

Configure your organisation's password requirements.

Typical settings include:

  • Enable Administrator Account Management
  • Password Complexity
  • Password Length
  • Password Age
  • Automatic Password Rotation
  • Backup Directory
  • Post Authentication Actions

For example:

  • Password Length: 14–16 characters
  • Complexity: Large letters, small letters, numbers, and special characters
  • Password Age: 30 days

Choose values that align with your organisation's security standards.


Step 4: Configure Backup Location

Microsoft LAPS allows passwords to be backed up securely.

Available options include:

  • Microsoft Entra ID
  • Active Directory (Hybrid environments)

Organisations using cloud-native management typically choose Microsoft Entra ID for secure password storage and simplified administration.


Step 5: Assign the Policy

After configuring the settings, assign the policy to the appropriate device group.

You can assign it to:

  • Pilot devices
  • IT department
  • Production devices
  • Dynamic device groups

Starting with a pilot deployment helps validate the configuration before rolling it out organisation-wide.


Step 6: Review and Deploy

Carefully review all configured settings.

Confirm:

  • Password policy
  • Backup directory
  • Password rotation
  • Device assignments

Click Create to deploy the Microsoft LAPS policy.

The policy will begin syncing with assigned devices during their next Intune check-in.


Step 7: Verify Policy Deployment

Once deployment is complete, verify that devices have received the policy.

In Microsoft Intune:

  • Open the device
  • Review Device Configuration
  • Confirm policy status
  • Check compliance

A successful deployment indicates that Windows LAPS is active on the device.


Step 8: Retrieve the Local Administrator Password

When needed, administrators can securely retrieve the password.

Navigate to:

Devices → Select Device → Local Administrator Password

You'll be able to view:

  • Current password
  • Password expiration date
  • Rotation status

Only authorised administrators should have permission to retrieve these passwords.


Best Practices for Microsoft LAPS Deployment

To maximise security and operational efficiency:

  • Use strong password complexity requirements.
  • Rotate passwords regularly.
  • Limit password retrieval permissions.
  • Enable audit logging.
  • Test deployments with a pilot group first.
  • Review password expiration policies periodically.
  • Keep Windows devices updated.
  • Monitor deployment status in Intune.
  • Remove unnecessary local administrator accounts.
  • Follow the principle of least privilege.

Implementing these practices helps strengthen endpoint security across your environment.


Common Deployment Issues

Policy Not Applying

Possible causes:

  • Device not enrolled in Intune
  • Incorrect assignment group
  • Device sync pending
  • Unsupported Windows version

Password Not Visible

Verify:

  • Backup directory configuration
  • Administrative permissions
  • Successful policy deployment
  • Device synchronisation status

Password Rotation Not Working

Check:

  • Password age policy
  • Device connectivity
  • Windows updates
  • Event logs for LAPS-related errors

Troubleshooting these areas resolves most deployment issues.


Security Benefits of Microsoft LAPS

Organisations adopting Microsoft LAPS gain several advantages:

  • Reduced credential theft risk
  • Protection against lateral movement
  • Automated password management
  • Improved compliance
  • Better endpoint security
  • Simplified administration
  • Reduced help desk workload
  • Stronger Zero Trust security posture

These benefits make Microsoft LAPS an essential component of modern endpoint security strategies.


Frequently Asked Questions

Is Microsoft LAPS free?

Microsoft LAPS is built into supported versions of Windows and can be managed through Microsoft Intune or Active Directory, depending on your environment.

Can Microsoft LAPS work with Microsoft Entra ID?

Yes. Windows LAPS supports password backup to Microsoft Entra ID for cloud-managed devices.

Does Microsoft LAPS replace the legacy LAPS solution?

Yes. Windows LAPS is Microsoft's modern, built-in solution and is recommended for new deployments.

How often should passwords rotate?

Most organizations configure password rotation every 30 days, though the ideal interval depends on security policies and compliance requirements.


Conclusion

Microsoft LAPS, combined with Microsoft Intune, provides a secure and scalable way to manage local administrator passwords across Windows devices. By automating password generation, enforcing rotation policies, and securely storing credentials, organizations can significantly reduce the risk associated with shared or static administrator passwords.

Following the deployment steps outlined in this guide will help you implement Microsoft LAPS efficiently while improving your overall endpoint security posture. Whether you're deploying to a small business or a large enterprise, Microsoft LAPS and Intune offer a streamlined approach to protecting privileged local accounts.

Comments

Popular posts from this blog

Endpoint Security Assessment Checklist for Small and Large Enterprises

Zero Trust vs VPN for Remote Access: Pros, Cons, and Risks

What Services Does a Microsoft Azure Services Provider in India Offer