Windows LAPS with Intune: unique local admin passwords in minutes
If every PC shares the same local administrator password, one compromised machine means all of them. Windows LAPS fixes that, and it's built into Windows and Intune.
On this page
A shared local admin password is a gift to attackers: compromise one device, extract the password hash, and move laterally to every other device with the same password. Windows LAPS gives every device its own random local admin password, rotates it automatically and backs it up to Entra ID.
Shared local admin password
- Same password on every PC
- One compromise opens them all
- Rarely changed
Windows LAPS
- Unique random password per device
- Rotated automatically
- Backed up to Entra ID with audited access
- 01Enable LAPS in Entra
- 02Intune LAPS policy
- 03Device rotates password
- 04Backed up to Entra ID
- 05Audited retrieval
1. Enable LAPS in Entra
In the Entra admin center, go to Devices → Device settings and set Enable Microsoft Entra Local Administrator Password Solution (LAPS) to Yes. Without this, devices can't back up their passwords.
2. Create the Intune policy
In Intune, go to Endpoint security → Account protection and create a Local admin password solution (Windows LAPS) policy:
- Backup directory: Backup the password to Azure AD only (Entra ID).
- Password age: such as 30 days.
- Password complexity and length: large letters, small letters, numbers and specials, at least 14 characters.
- Post-authentication actions: reset the password, and optionally log off, after the password is used. This stops a retrieved password staying valid.
If you've renamed the built-in Administrator account or use a custom one, set Administrator account name to match.
3. Retrieve a password
In Intune, open the device and choose Local admin password. Retrievals are audited. Give the permission only to roles that need it, such as a custom role for the service desk.
4. Rotate on demand
Use the Rotate local admin password remote action after a password has been shared during a support call.
Checking it's working
- In Intune, the device's Local admin password page shows when the password was last rotated.
- On the device, Event Viewer has a dedicated log at Applications and Services Logs → Microsoft → Windows → LAPS.
- In PowerShell on the device,
Get-LapsDiagnosticscollects logs for troubleshooting.
Common problems
- No password shown: check the Entra device setting for LAPS is enabled. Without it, the backup is rejected.
- Wrong account managed: if you renamed the built-in Administrator, set the account name in the policy.
- Conflicts: remove old LAPS Group Policy settings or the legacy LAPS client to avoid two policies fighting.