mandreou's avatar
mandreou
Brass Contributor
May 04, 2023
Status:
Completed

Make the LAPS tab available to non-domain admins on ADUC (RSAT)

Currently, the tab is only available to Domain Admins and the rest of our delegated admins can only use PowerShell.

6 Comments

  • billlight's avatar
    billlight
    Copper Contributor

    We're in a stig heavy environment running Windows 11 23h2. The laps tab is available in ADUC on our Test workstation but unfortunately, we don't have any documents as to how it was fixed.

     

    System> Optional features is not an option for installing RSAT on management workstations, what PowerShell commands are available for a win 11 client to ensure we have the newest RSAT tools and anything else related to properly utilize and have the LAPS tab available for computer object's within ADUC?

  • I have added documentation here that describes how to get access to the new LAPS-enabled ADUC, including via RSAT on Windows 11 and Windows 10:

     

    Windows LAPS Snap-in Availability

     

    There are no plans to make the new LAPS-enabled ADUC available on any older platforms or in older versions of RSAT, including the externally installed pkg version of RSAT.

  • mandreou - I've tested Windows 11 and Windows 10 with RSAT installed and the new LAPS-enabled ADUC tab IS present in that configuration.  And the new new LAPS-enabled ADUC tab shows up just fine on those client SKUs for a non-Domain Admin.  Can you clarify where you are not seeing the new LAPS-enabled ADUC tab?

  • mandreou - thanks for the feedback.  Adding the new LAPS-enabled ADUC to RSAT is something I am actively looking into.  No ETA at this time.

     

    One question: I keep hearing that non-Domain Admins are not able to see the new LAPS ADUC tab.  I was unable to repro this - I tested by logging into a Server sku as a non-DA account and running ADUC - the LAPS tab showed up fine.   So I am interpreting the comment "non-Domain Admins cannot see the LAPS tab" to really mean "the new LAPS-enabled ADUC is not available on client SKUs" (ie via RSAT).   Please correct me if this interpretation is incorrect.