Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute“Azure AD LAPS” is older terminology: Azure AD is now Microsoft Entra ID, and Windows 11 uses built-in Windows LAPS. Use an Intune policy through the Windows LAPS CSP for Microsoft Entra-joined devices; use Windows LAPS Group Policy for Active Directory domain-joined devices and domain controllers. The password backup destination must match the device scenario.
Choose the right management path
Windows LAPS manages a local administrator password, rotates it, and backs up the password and related metadata to Microsoft Entra ID or Windows Server Active Directory. This reduces reliance on shared or long-lived local administrator credentials, but does not by itself eliminate pass-the-hash or lateral-movement risks. It can also run configured post-authentication actions after a managed password is used.
| Device scenario | Management method | Backup destination |
|---|---|---|
| Microsoft Entra joined | Intune Windows LAPS policy | Microsoft Entra ID |
| Microsoft Entra hybrid joined | Intune Windows LAPS policy | Microsoft Entra ID or Active Directory, according to the supported design |
| Active Directory domain joined | Windows LAPS Group Policy | Windows Server Active Directory |
| Domain controller; DSRM password management | Windows LAPS Group Policy | Windows Server Active Directory |
| Workplace-joined or personal device | Intune Windows LAPS is not supported for this scenario | Not applicable |
Microsoft documents Group Policy and the configuration service provider (CSP) as distinct policy mechanisms. For an Entra-only Windows 11 device, use Intune rather than treating traditional LAPS Group Policy as the normal management path: Windows LAPS policy settings and Intune Windows LAPS overview.
Prerequisites to check first
- Confirm the join state. Classify each device as Entra joined, hybrid joined, AD domain joined, or workplace joined before choosing a backup directory. A policy can arrive on a device yet fail operationally if the target directory does not fit its join state.
- Check Windows servicing. Microsoft’s Intune prerequisites currently list Windows 11 22H2 build 22621.1555 or later with KB5025239, and Windows 11 21H2 build 22000.1817 or later with KB5025224. Verify current cumulative updates rather than relying only on the Windows marketing version; Microsoft may update its support requirements. See Microsoft’s current prerequisites.
- For Intune, enroll the device and assign a policy. Microsoft documents Intune Plan 1 and Microsoft Entra ID Free among the prerequisites for this capability; confirm current tenant licensing and role requirements before deployment.
- Enable Entra LAPS for Entra-joined devices. In the Microsoft Entra admin center, go to Identity > Devices > Overview > Device settings, set Enable Local Administrator Password Solution (LAPS) to Yes, and save. Hybrid scenarios have different requirements; confirm the chosen backup destination and tenant/device configuration rather than assuming this Entra-only prerequisite applies identically.
- Plan the account. The built-in Administrator account is the default target. In manual mode, a custom account must already exist; Windows LAPS does not create it. Automatic account management is available starting with Windows 11 24H2.
- Plan access separately from policy deployment. The permissions needed to configure policy, read metadata, retrieve a clear-text password, and request rotation are not interchangeable.
For feature details and current supported platforms, see Microsoft’s Intune Windows LAPS overview and Windows LAPS CSP documentation.
#1 Best Overall
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
Configure Windows LAPS in Intune
- Open the Microsoft Intune admin center and go to Endpoint security > Account protection.
- Select Create Policy, choose Windows for the platform, and select Local admin password solution (Windows LAPS) as the profile.
- Set the backup directory to match the device scenario. For Entra-backed cloud-native devices, choose Microsoft Entra ID. Use AD backup only where the device and organization’s design support it.
- Configure the managed account and password lifecycle settings. Begin with a pilot configuration, and separate settings for older Windows releases from 24H2-only features.
- Assign the policy to a pilot device group, then review policy status and device-level results before expanding deployment. Microsoft warns that user-group assignments can cause configurations to change as different users sign in, creating account-management conflicts.
Microsoft’s current workflow and setting descriptions are in Create and manage Windows LAPS policies in Intune.
A practical starting configuration
The values below are operational recommendations, not universal Microsoft requirements. Validate them against help-desk procedures and local password policy before broad deployment.
| Setting | Suggested starting point | Qualification |
|---|---|---|
| Backup directory | Microsoft Entra ID for cloud-native devices; AD for traditional domain devices | Must match the supported device and directory design. |
| Managed account | Built-in Administrator initially | Use a custom or automatically managed account only with an intentional account plan. |
| Password age | 30 days | Operational choice; Entra backup requires at least 7 days. |
| Password length | 20–24 characters where compatible | Check the device’s local password policy. |
| Password complexity | 4 on pre-24H2 devices | Values 5–8 require Windows 11 24H2 or later. |
| Password expiration protection | Enabled where supported | AD-specific setting; not available for Entra backup. |
| Post-authentication reset delay | Choose a short delay compatible with support workflows | Balance exposure reduction against disrupting legitimate help-desk work. |
| Policy assignment | Pilot and production device groups | Avoid broad user-group assignments for LAPS configuration. |
Configure Windows LAPS through Group Policy
Use this route for AD domain-joined computers and domain-controller DSRM password management. The Windows LAPS administrative template is installed with Windows at %windir%PolicyDefinitionsLAPS.admx. In an environment using a Group Policy Central Store, copy the current LAPS ADMX and its language files there manually; Windows Update does not copy them into the Central Store.
Rank #2
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
- In Group Policy Management Editor, open Computer Configuration > Policies > Administrative Templates > System > LAPS.
- For AD password backup, configure
BackupDirectory = 2. The values are 0 for disabled, 1 for Microsoft Entra ID, and 2 for Windows Server Active Directory. If backup is disabled, other LAPS settings are ignored. - Choose the managed account and set password age, length, complexity, and post-authentication behavior. If specifying a custom account in manual mode, create it before applying the policy.
- For AD backup, decide whether to enable password encryption, specify the authorized decryption principal, and retain encrypted password history. AD password encryption requires an AD Domain Functional Level of 2016 or later.
- For domain controllers, configure DSRM password backup where required. This setting is a Group Policy/domain-controller scenario; the LAPS CSP does not support it.
- Delegate read and decryption rights to the appropriate groups, then pilot the GPO and verify that devices are processing the intended policy.
See Microsoft’s Windows LAPS policy settings and Active Directory deployment scenario.
Understand the settings and version limits
| Setting | Purpose and scope | Documented value or behavior |
|---|---|---|
BackupDirectory |
Selects where credentials are stored; Entra or AD | 0 disabled; 1 Entra ID; 2 AD. |
AdministratorAccountName |
Selects the local account to manage | Built-in Administrator is the default. |
PasswordAgeDays |
Maximum password age | 1–365 days; default 30. Entra backup requires at least 7 days. Changing the age does not necessarily rotate the current password immediately. |
PasswordLength |
Password length | 8–64 characters; default 14. |
PasswordComplexity |
Character-class or newer passphrase-related complexity mode | Default 4 (uppercase, lowercase, numbers, and special characters). Values 5–8 require Windows 11 24H2, Windows Server 2025, or later. |
PassphraseLength |
Number of words in a generated passphrase | 3–10 words; Windows 11 24H2, Windows Server 2025, or later. |
PostAuthenticationResetDelay |
Delay after password expiration before the configured action | Default 24 hours. |
PostAuthenticationActions |
Actions after password expiration | Default behavior resets the password and signs out. |
PasswordExpirationProtectionEnabled |
Prevents password expiry from exceeding policy | AD setting; default true. |
ADPasswordEncryptionEnabled |
Encrypts passwords backed up to AD | AD only; requires Domain Functional Level 2016 or later. |
ADPasswordEncryptionPrincipal |
Specifies who can decrypt AD-stored passwords | AD only; defaults to Domain Admins if unspecified. |
ADEncryptedPasswordHistorySize |
Number of encrypted historical AD passwords retained | AD only; 0–12. |
ADBackupDSRMPassword |
AD and Group Policy/domain-controller scenario only. | |
AutomaticAccountManagementEnabled and related automatic-account settings |
Enables automatic account management and selects or names the target account | Windows 11 24H2 and later. Related options include account target, name or prefix, whether to enable the account, and randomized naming. |
For exact policy definitions and compatibility, consult Microsoft’s policy settings reference and password and passphrase guidance. If a configured length or complexity conflicts with local password policy, Windows LAPS can fail to generate a compatible password; Microsoft identifies event 10027 as a relevant failure indicator.
Verify that policy processed and a password was backed up
Windows LAPS processes active policy periodically. To request processing immediately on a test device, run this from an elevated PowerShell session:
Rank #3
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Invoke-LapsPolicyProcessing
For Microsoft Entra backup, Microsoft identifies event 10029 as a successful password-update event. Also check the Intune device’s policy status and confirm that the device object is enabled and the expected backup destination is configured. For AD deployment, verify the device is domain joined, can reach the domain as needed, and that the required AD permissions and policy are in place.
Microsoft’s Entra deployment guidance is available at Windows LAPS with Microsoft Entra ID.
Recommended Free Tools
Retrieve or rotate the managed password
Microsoft Entra-backed credentials
In Intune, open Devices > All devices, select the Windows device, then under Monitor select Local admin password. The page can show the account name and rotation information, and the clear-text password when it is backed up to Microsoft Entra ID. Viewing the password requires the relevant Entra permission, including microsoft.directory/deviceLocalCredentials/password/read, and creates an audit event.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
PowerShell retrieval is also available:
Get-LapsAADPassword -DeviceIds <device-id> -IncludePasswords
Clear-text retrieval requires Microsoft Graph permission DeviceLocalCredential.Read.All; metadata-only access uses DeviceLocalCredential.ReadBasic.All. Use least privilege and grant password-reading access only to administrators who need it. See Get-LapsAADPassword.
AD-backed credentials
The Intune Local admin password page does not display passwords backed up to on-premises AD. Use the Windows LAPS Active Directory tooling and the permissions delegated for that environment, such as Get-LapsADPassword.
Request an early rotation
For an Entra-backed device, use Devices > All devices > [device] > Rotate Local admin password in Intune. The device must be Entra joined or hybrid joined and actively backing up through Windows LAPS to Entra ID. The administrator needs the Intune remote-task permission for rotation, along with the applicable managed-device and organization read permissions. Details are in Microsoft’s rotation action documentation.
Best Value
- 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
- Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
- 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
- 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
- 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
For an AD-managed device, an administrator can request policy processing and use:
Reset-LapsPassword
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot common failures
| Symptom | What to check |
|---|---|
| Policy appears assigned but no password is backed up | Confirm BackupDirectory is not disabled and matches the join state; enable Entra LAPS for Entra-joined devices; confirm the device is supported and updated, enabled in Entra where applicable, and not merely workplace joined. Check whether a higher-precedence CSP policy is active. |
| Custom account is not managed | In manual account-management mode, create and enable the custom account first. Automatic account management requires Windows 11 24H2 or later. |
| Password cannot be viewed in Intune | Confirm the credential is backed up to Entra ID, not AD; confirm the administrator has password-read permission. AD-backed credentials require the AD retrieval method. |
| Rotate action is missing or unavailable | Check corporate device eligibility, Entra or hybrid join, active Entra backup, and the Intune remote-task role permissions for rotation. |
| Password generation fails | Check local password policy compatibility with configured length and complexity; review event 10027. Use separate policies or filters when a setting is only supported on 24H2 and later. |
| Newer complexity or passphrase setting behaves differently across devices | Values 5–8 and passphrase settings require Windows 11 24H2 or later. Do not assume an older release supports those features. |
Microsoft’s Intune troubleshooting and requirements reference is the Windows LAPS overview; policy-specific behavior is documented in the policy settings reference.
Prevent policy conflicts and credential loss
Windows LAPS has separate policy roots for CSP, Windows LAPS Group Policy, local configuration, and legacy Microsoft LAPS. The CSP policy root takes precedence over the Windows LAPS Group Policy root. If multiple management systems are configured, Windows LAPS selects the active policy root rather than merging each setting across roots; missing settings in the selected root use defaults. Therefore, an Intune LAPS policy can supersede an existing GPO configuration. Avoid simultaneously managing the same device through Intune, GPO, and legacy Microsoft LAPS unless the transition is deliberately planned.
Protect the Entra device object lifecycle: Microsoft states that deleting a device object also deletes its associated LAPS credential from Entra ID, with no Entra recovery method unless the organization has a separate workflow for retrieving and storing credentials externally. Treat device deletion as a security-sensitive operation, not as a harmless cleanup step. AD deployments should likewise limit credential retrieval and decryption rights to designated groups.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteFor background on the distinction between the built-in Windows LAPS system and earlier LAPS management, see Microsoft’s Windows LAPS overview and LAPS CSP reference.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




