Windows LAPS Guide: One Admin Password Per Laptop
GuideWindows LAPS is built into Windows and gives every laptop its own local admin password, rotated on a schedule and backed up to Microsoft Entra ID or Active Directory. This guide walks a small office through switching it on with Intune, proving it worked, and getting a password back on the day someone actually needs one.
One admin password per laptop, changed for you
Most small offices have one local admin password, and every laptop knows it. It was set the week the first machine arrived, it lives on a sticky note or in a former employee's memory, and anyone who lifts it from one laptop has the keys to all of them. Microsoft's own documentation puts it plainly: shared local admin passwords are how attackers move sideways from one machine to the next.
Windows LAPS (Local Administrator Password Solution) fixes that without buying anything. Each laptop gets its own long, random admin password. Windows changes it on a schedule, backs it up to your directory, and lets the people you choose read it back when a machine needs rescuing.
For the owner, in one line: after this, losing one laptop's admin password costs you one laptop, not the whole office.
What you need before you start
- Windows 11 23H2 or later. LAPS is built in. Older Windows 11 and Windows 10 builds got it in the April 11, 2023 update.
- A directory to hold the passwords. Laptops joined to Microsoft Entra ID back up to Entra ID; laptops joined to on-premises Active Directory back up to AD. A hybrid-joined laptop can use either, but never both at once.
- Licensing: LAPS itself costs nothing, and Entra ID Free is enough to store passwords. The Intune route below needs Microsoft Intune Plan 1.
- Not supported: devices that are only workplace-joined (registered) to Entra ID, rather than joined.
If you still run the old Microsoft LAPS download from 2016, retire it. It is deprecated as of Windows 11 23H2, and newer Windows versions block its installer.
Step 1: Let Entra ID accept the passwords
Entra ID refuses LAPS passwords until you tell it otherwise, and this is the step people skip.
- Sign in to the Microsoft Entra admin center as a Cloud Device Administrator.
- Go to Identity > Devices > Overview > Device settings.
- Set Enable Local Administrator Password Solution (LAPS) to Yes and select Save.
Step 2: Create the LAPS policy in Intune
- In the Intune admin center, go to Endpoint security > Account protection and select Create Policy.
- Set Platform to Windows and Profile to Local admin password solution (Windows LAPS).
- Set Backup Directory to back up to Microsoft Entra ID (or Active Directory for domain-joined laptops). Leave it unset and nothing is backed up at all.
- Assign the policy to a device group, not a user group. User groups make the policy follow people between laptops, which changes the settings every time someone new signs in.
Leave Administrator Account Name blank and LAPS manages the built-in Administrator account, found by its well-known ID rather than its name. If you name a custom account instead, that account has to exist already: LAPS only creates accounts on Windows 11 24H2 and later, through automatic account management.
The defaults are sensible, so you only need to touch them on purpose:
| Setting | Default | What it means |
|---|---|---|
| Password age | 30 days | Rotates monthly. Entra ID needs at least 7 |
| Password length | 14 characters | 8 to 64 allowed |
| Complexity | Upper, lower, numbers, symbols | The level Microsoft recommends as the minimum |
| Post-authentication delay | 24 hours | Grace period after someone uses the password |
| Post-authentication action | Reset password and sign out | The used password stops working after the grace period |
That last pair is the quiet hero. Once a technician signs in with the LAPS password, Windows changes it again after the grace period, so a password read for one rescue does not stay valid for the next month.
Give each laptop exactly one LAPS policy. Two policies with conflicting settings can stop the backup entirely, and Intune policy overrides any LAPS settings from Group Policy or the old download.
Step 3: Prove it worked
Don't wait for the hourly cycle. On one laptop, in an elevated PowerShell window:
Invoke-LapsPolicyProcessing
Then open Event Viewer at Applications and Services Logs > Microsoft > Windows > LAPS > Operational. Each processing run starts with event 10003 and ends with 10004. The line that matters is event 10029: the password reached Entra ID. Event 10005 means the run failed, and the events just before it say why.
The most common failure is event 10027, which means your local password policy demands something LAPS isn't generating. Run net accounts on the laptop and line the two up.
Step 4: Get a password back when you need one
In the Intune admin center, go to Devices > All devices, open the laptop, and under Monitor select Local admin password. Select Show to reveal it. Every view is written to the audit log, which is exactly what you want from a master key.
To read it from PowerShell instead, the LAPS module wraps Microsoft Graph. You need an Entra app registration with Device.Read.All and DeviceLocalCredential.Read.All, then:
Connect-MgGraph -TenantId <tenant-id> -ClientId <app-id>
Get-LapsAADPassword -DeviceIds <device-name> -IncludePasswords -AsPlainText
Keep -AsPlainText for the moment of need, not for scripts that log their output.
Step 5: Rotate early after a departure or a repair
After a technician leaves, or a laptop comes back from repair, rotate the password instead of waiting for day 30. In Intune, open the device, select the ... menu and choose Rotate local admin password. The laptop must be online, and you rotate one device at a time.
No built-in Intune role includes that button. Create a custom role with Managed devices: Read, Organization: Read and Remote tasks: Rotate Local Admin Password, and give it to the people who should have it.
On the laptop itself, you can force the same thing:
Reset-LapsPassword
Two ways to lose a password for good
- Deleting the device in Entra ID deletes its LAPS password with it. There is no recovery. Retrieve the password before you delete a device you might still need to get into.
- A disabled device stops rotating. LAPS only rotates and backs up for devices that are enabled in Entra ID.
Using on-premises Active Directory instead
Domain-joined laptops follow the same idea through Group Policy: Computer Configuration > Policies > Administrative Templates > System > LAPS. Extend the schema once with Update-LapsADSchema, let computers write their own passwords with Set-LapsADComputerSelfPermission -Identity <OU>, and copy LAPS.admx to your central store yourself, because Windows Update won't. Password encryption in AD is on by default and needs a 2016 domain functional level.
Sources
Checked against Microsoft Learn on 2026-10-03:
More in Windows laptops
- Microsoft Security Compliance Toolkit
- App Control for Business (formerly WDAC)
- HardeningKitty
- Windows Supply Chain Security Guide
- Windows LAPS Guide: One Admin Password Per Laptop
- BitLocker Guide: Encrypt Every Laptop, Keep Every Key