Event banner
Windows LAPS: enhancements and roadmap
Event Ended
Wednesday, Nov 29, 2023, 10:30 AM PSTEvent details
Learn about recent improvements to Windows LAPS and how they can help you deploy and use the feature. Also learn about the future plans we are working on!
This session is part of the Mi...
Char_Cheesman
Updated Dec 27, 2024
Thomas Haller
Nov 29, 2023Copper Contributor
Is the new GUI just for onPrem password retrieval? Any plans for Azure AD/EntraID scenarios (e.g. user can get the admin password via Company Portal if allowed)?
JaySimmons
Microsoft
Nov 29, 2023We are planning the new GUI only for onprem AD password retrieval. In theory one could be done for AAD\Entra but those products have mgmt portals which already make it easy.
- jabbrwckyNov 29, 2023Brass ContributorIt’s definitely not a streamlined process though. For a helpdesk person who does this dozens of times a day (we have pretty locked-down student devices so almost every incident requires an elevation) it’s a real pain. Would it be possible to make something similar with Graph API?
- Charlie DobsonNov 29, 2023Iron ContributorShouldn't the helpdesk people have their own privileged accounts? I generally try to discourage using local admin accounts unless it's truly necessary.
- JaySimmonsNov 29, 2023
Microsoft
In the end the decision is up to the customer, but there are some good reasons for using local accounts for a helpdesk\break-glass style situation. One benefit is that if you are concerned that the device might be compromised, you are not making things any worse by authenticating to it with a local account that already belongs to that device (blast-area-reduction measure as it's sometimes described).
- JaySimmonsNov 29, 2023
Microsoft
Hi Chris yes a fat GUI to retrieve passwords could be built on top of Graph API with modern auth, no problem. Appreciate your feedback, will add it to my list for consideration.