LAPS (original) (raw)

Local Administrator Password Solution

The "Local Administrator Password Solution" (LAPS) provides a centralized storage of secrets/passwords in Active Directory (AD) - without additional computers. Each organization’s domain administrators determine which users, such as helpdesk admins, are authorized to read the passwords.

For occasions when login is required without domain credentials, password management can become complex. LAPS simplifies password management while helping customers implement recommended defenses against cyberattacks. In particular, it mitigates the risk of lateral escalation that results when customers have the same administrative local account and password combination on many computers.

Why use LAPS instead of other password managers/vaults?

Other password managers typically require either, additional hardware (IIS/SQL), trusting a third party, or ad hoc practices (Excel spreadsheet of passwords = huge security hole).

LAPS provides a streamlined approach to:

Components

Solution automatically manages the .500 (local administrator) password on domain joined computers, so the password is:

Solution is built upon AD infrastructure, so there is no need to install and support other technologies.

Solution itself is a Group Policy Client Side Extension that is installed on managed machines and performs all management tasks

Management tools delivered with the solution allow for easy configuration and administration.

Core of the solution is GPO Client side Extension (CSE) that performs the following tasks during GPO update:

Security

Manageability

Requirements

FAQs

Where can I download LAPS?

You can download the tool from the download center here.

Is LAPS officially supported?

LAPS customer support is available through Microsoft Premier Support Services.

Where can I see further details, architectural diagrams and granular installation instructions?

See the documentation via LAPS download link

Where can I find installation instructions?

See the documentation via LAPS download link

Are there any known compatibility issues?

Yes. Administrator password management via Group Policy Preferences (GPP) collides with LAPS, event after hotfix MS014-025 installed. Management of administrator account password needs to be removed from GPP prior installing LAPS

What is new in 6.1 version?

What is new in 6.2 version?