azureblog.co.uk
← cd ~/posts

Windows LAPS with Intune: unique local admin passwords in minutes

If every PC shares the same local administrator password, one compromised machine means all of them. Windows LAPS fixes that, and it's built into Windows and Intune.

2 min read✓ checked 29 Jul 2026Intune · Windows · Security
On this page
  1. 1. Enable LAPS in Entra
  2. 2. Create the Intune policy
  3. 3. Retrieve a password
  4. 4. Rotate on demand
  5. Checking it's working
  6. Common problems

A shared local admin password is a gift to attackers: compromise one device, extract the password hash, and move laterally to every other device with the same password. Windows LAPS gives every device its own random local admin password, rotates it automatically and backs it up to Entra ID.

Shared local admin password

  • Same password on every PC
  • One compromise opens them all
  • Rarely changed

Windows LAPS

  • Unique random password per device
  • Rotated automatically
  • Backed up to Entra ID with audited access
Before and after Windows LAPS.
  1. 01Enable LAPS in Entra
  2. 02Intune LAPS policy
  3. 03Device rotates password
  4. 04Backed up to Entra ID
  5. 05Audited retrieval

1. Enable LAPS in Entra

In the Entra admin center, go to Devices → Device settings and set Enable Microsoft Entra Local Administrator Password Solution (LAPS) to Yes. Without this, devices can't back up their passwords.

2. Create the Intune policy

In Intune, go to Endpoint security → Account protection and create a Local admin password solution (Windows LAPS) policy:

  • Backup directory: Backup the password to Azure AD only (Entra ID).
  • Password age: such as 30 days.
  • Password complexity and length: large letters, small letters, numbers and specials, at least 14 characters.
  • Post-authentication actions: reset the password, and optionally log off, after the password is used. This stops a retrieved password staying valid.

If you've renamed the built-in Administrator account or use a custom one, set Administrator account name to match.

3. Retrieve a password

In Intune, open the device and choose Local admin password. Retrievals are audited. Give the permission only to roles that need it, such as a custom role for the service desk.

TechnicianIntune / EntraDeviceViews local admin password1Retrieval auditedUses password to sign in locally3Post-authentication action:reset passwordNew password backed up5
A service desk retrieval, start to finish.

4. Rotate on demand

Use the Rotate local admin password remote action after a password has been shared during a support call.

Don't forget the legacy client: if devices still run the old Microsoft (the separate MSI), plan to remove it. Windows LAPS is built into supported Windows versions.

Checking it's working

  • In Intune, the device's Local admin password page shows when the password was last rotated.
  • On the device, Event Viewer has a dedicated log at Applications and Services Logs → Microsoft → Windows → LAPS.
  • In PowerShell on the device, Get-LapsDiagnostics collects logs for troubleshooting.

Common problems

  • No password shown: check the Entra device setting for LAPS is enabled. Without it, the backup is rejected.
  • Wrong account managed: if you renamed the built-in Administrator, set the account name in the policy.
  • Conflicts: remove old LAPS Group Policy settings or the legacy LAPS client to avoid two policies fighting.
Next in Intune for Windows, start to finish · part 4 of 6Why Edge suddenly switched language on a whole office →