How to Install and Configure Microsoft LAPS (Local Administrator Password Solution)

Spread the love

 

๐Ÿ“Œ Introduction

Microsoft Local Administrator Password Solution (LAPS) is a free tool that enhances security by automatically managing local administrator passwords on domain-joined computers. This guide will walk you through the installation and configuration of LAPS in a step-by-step manner.


๐Ÿ” Prerequisites

Before you begin, ensure you have the following:

โœ… Active Directory configured
โœ… Domain Admin or equivalent privileges
โœ… Windows Server with Group Policy Management
โœ… Windows Clients (Windows 10/11) joined to the domain


๐Ÿ“ฅ Step 1: Download and Install LAPS

1๏ธโƒฃ Download LAPS from the official Microsoft Download Center:
๐Ÿ‘‰ https://www.microsoft.com/en-us/download/details.aspx?id=46899

2๏ธโƒฃ Run the LAPS.x64.msi installer on your Domain Controller (DC) and client machines.

3๏ธโƒฃ On the Installation Wizard, select:

  • โœ… AdmPwd GPO Extension

  • โœ… PowerShell Module

  • โœ… Management Tools

4๏ธโƒฃ Click Install and wait for the process to complete.


๐Ÿ”— Step 2: Extend Active Directory Schema

To store the LAPS-managed passwords, you need to extend the AD schema.

1๏ธโƒฃ Open PowerShell as Administrator on your Domain Controller.

2๏ธโƒฃ Run the following command:

Import-Module AdmPwd.PS
Update-AdmPwdADSchema

3๏ธโƒฃ If successful, youโ€™ll see no error messages.


๐ŸŽ›๏ธ Step 3: Set Permissions in Active Directory

Now, grant computers permission to update their password attributes.

1๏ธโƒฃ Run this command in PowerShell:

Set-AdmPwdComputerSelfPermission -OrgUnit "OU=Computers,DC=yourdomain,DC=com"

๐Ÿ”น Replace OU=Computers,DC=yourdomain,DC=com with your actual Organizational Unit (OU) path.

2๏ธโƒฃ Grant read permission for IT admins to retrieve passwords:

Set-AdmPwdReadPasswordPermission -OrgUnit "OU=Computers,DC=yourdomain,DC=com" -AllowedPrincipals "ITAdmins"

3๏ธโƒฃ Ensure only necessary users can reset passwords:

Set-AdmPwdResetPasswordPermission -OrgUnit "OU=Computers,DC=yourdomain,DC=com" -AllowedPrincipals "ITAdmins"

โœ… Done! Now, the computers in the OU can update their local administrator passwords securely.


๐ŸŽ›๏ธ Step 4: Configure LAPS Group Policy

1๏ธโƒฃ Open Group Policy Management (gpmc.msc).

2๏ธโƒฃ Navigate to Computer Configuration > Administrative Templates > LAPS.

3๏ธโƒฃ Enable the following policies:

  • Enable local admin password management โ†’ Set to Enabled โœ…

  • Password Settings โ†’ Configure password complexity, length, and expiration โœ…

  • Name of administrator account to manage (if you use a custom local admin name) โœ…

4๏ธโƒฃ Link the policy to the OU where the computers are located.


๐Ÿ”Ž Step 5: Verify LAPS Deployment

1๏ธโƒฃ Force Group Policy Update:

gpupdate /force

2๏ธโƒฃ On a domain-joined PC, run:

Get-AdmPwdPassword -ComputerName PC-01 -Credential (Get-Credential)

๐Ÿ”น This will show the stored local admin password for that computer.

โœ… Success! Your LAPS deployment is now active.


๐ŸŽฏ Conclusion

Youโ€™ve successfully installed and configured Microsoft LAPS! ๐Ÿ† This enhances security by ensuring each machine has a unique, automatically updated local administrator password.

๐Ÿ“ข Next Steps:

  • โœ… Monitor password changes using PowerShell

  • โœ… Train your IT team on LAPS password retrieval

  • โœ… Consider Windows LAPS (Newer Version) for enhanced security features

๐Ÿ’ฌ Need help? Drop your questions in the comments! ๐Ÿš€

Leave a Reply

Your email address will not be published. Required fields are marked *

×