Event details
What? Can it be? A session on LAPS? Yes!! The Local Administrator Password Solution (LAPS) has been widely used by IT pros for nearly a decade to secure Windows devices, aid in device recovery, and support helpdesk scenarios—and now we’re modernizing and improving this technology. First, we’re making it native to Windows. Second, we’re adding new features like backing up passwords to Azure AD, DSRM password backup, AD password encryption, and more. Get a inside look at the design and implementation of the new and improved LAPS, now available to Insiders in the Windows 11 Dev Channel*. *Azure scenarios are currently limited to private preview customers.
|
This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, RSVP for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
89 Comments
- GaryBaerBrass ContributorWhat will the new LAPS do with HAADJ devices? Will the LAP be stored on-prem and AAD, or just one or the other? Also, what about HAADJ Autopiloted devices which end up with two Azure device objects (one AADJ and one HAADJ)?
- JaySimmons
Microsoft
This new version of LAPS fully supports HAADJ devices. However, we only support storing the password in ONE directory at a time, not both. It's your choice to make via policy configuration.- GaryBaerBrass ContributorThank you for that... I assume then that only the HAADJ object in AAD will be attached to the LAPS environment? We've been trying to figure out how to resolve the multiple objects created when doing a HAADJ during Autopilot. Once the HAADJ device is ready to go, there is still a "disabled" AAD device object in Azure.
- DSTCopper ContributorDo we have any expected GA data so far?
- JaySimmons
Microsoft
CY23H1, hopefully early in that timeframe.- DSTCopper ContributorLooking forward to it! Thanks
- Marc_LafIron ContributorPlease tell me this will be back ported to Windows 10!
- Joe_Lurie
Microsoft
I'm curious, Marc, if this is only available in Windows 11, would that be a driver to help you convince your bosses and other teams that you should start the Windows 11 migration?- Greg_C_GilbertIron ContributorI suspect most large companies won't adopt this until 2025 after W10 support ends if W10 isn't supported. Even if we get most of our PCs migrated to 11, I can guarantee, there will be a few stragglers on 10 right up until the end. Please consider this as a reason to backport this to 10.
- JaySimmons
Microsoft
For now answer is "maybe". A win10 backport is definitely under consideration, not to get your hopes up too much, final approvals still pending.
- Rob de RoosIron ContributorMost of the time we disable and rename de local admin account. What is your take on that vs or in combination with LAPS?
- ESJeffLBrass ContributorRight curious how you handle the renamed admin account. We create another local account that is given to the support where the main admin account is only know by the SCCM/Desktop Team is never used.
- JaySimmons
Microsoft
That is fine. You can configure LAPS to manage a different local admin account of your choosing. This is an inherited feature from the legacy version of LAPS, not anything new in this new version of LAPS.- Greg_C_GilbertIron ContributorWill it be possible to manage more than one local account on a PC? We also create a standard account that is used by support in certain limited scenarios instead of using the admin account.
- John_SanchezCopper ContributorWill the password be made visible on the device via MEM via RBAC?
- JaySimmons
Microsoft
A customizable RBAC authz story is planned\being worked on, for now password retrieval is limited to the Global Administrator, Device Administrator, and Intune Administrator roles. Password retrieval is done via a Microsoft Graph query, however additional Intune\MEM integration is planned (note the new LAPS CSP).- John_SanchezCopper ContributorThank you for the reply! Is it safe to assume admin units PIM could be applied here (device admin role)
- Heather_Poulsen
Community Manager
Welcome to Managing local admin account passwords in AD and Azure AD at the Microsoft Technical Takeoff. Let's get started! Have a question? Post it here in the Comments. Subject matter experts will be answering during the session and throughout the week. We're looking forward to the conversation.
- kavanozCopper ContributorWill we have to wait until the next version of Windows 11 (ie: 23H2) to use the AAD integration for LAPS or will the feature be backported to Windows 11 22H2?
- JaySimmons
Microsoft
Backports are planned however the final list of platforms is not yet approved. While things can change, I would say there is a good chance that Win11 22H2 will be included.
- CarolineDorionCopper ContributorIs there a way LAPS will help us manage, through Intune, the user who can be admin of all HAADJ computers not necessarily using the LAPS account ? There is role for the Admins for the AAD computers but we are struggling with the HAADJ admins.
- JaySimmons
Microsoft
I don't think so. You might consider posing this question to a more Intune-focused forum?
- ENT57Copper ContributorWill LAPS device passwords be stored in a delegate-able attribute in Azure like that used for BitLocker keys?
- JaySimmons
Microsoft
LAPS admin account passwords are stored on the AAD device object just like Bitlocker keys. A customizable RBAC authz story is planned\being worked on, for now password retrieval is limited to the Global Administrator, Device Administrator, and Intune Administrator roles.
- noliverdlrBrass ContributorWill there be a link to sign up to become a private preview customer? My firm is looking for a LAPS solution and I would like to show off this feature as something that may be something to wait for.
- JaySimmons
Microsoft
The LAPS AAD private preview is closed to additional customers. Stay tuned - we hope to open it up broadly by early next year. - AlexMagsInfraCopper ContributorRather than wait, you could deploy regular LAPS or Cloud LAPS for now, to reduce the risk of lateral movement via a common local admin password, and switch to the newer Azure AD LAPS later once it's GA and if it works for you? https://www.microsoft.com/en-us/download/details.aspx?id=46899 https://msendpointmgr.com/cloudlaps/
- silvermarkg_PersonalCopper ContributorIf using hybrid you could use regular LAPS or if using pure cloud you could just disable the local admin account