Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Active Directory

Windows LAPS for Windows 11: Choose Intune or Group Policy

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Azure AD LAPS” is older terminology: Azure AD is now Microsoft Entra ID, and Windows 11 uses built-in Windows LAPS. Use an Intune policy through the Windows LAPS CSP for Microsoft Entra-joined devices; use Windows LAPS Group Policy for Active Directory domain-joined devices and domain controllers. The password backup destination must match the device scenario.

Choose the right management path

Windows LAPS manages a local administrator password, rotates it, and backs up the password and related metadata to Microsoft Entra ID or Windows Server Active Directory. This reduces reliance on shared or long-lived local administrator credentials, but does not by itself eliminate pass-the-hash or lateral-movement risks. It can also run configured post-authentication actions after a managed password is used.

Device scenario Management method Backup destination
Microsoft Entra joined Intune Windows LAPS policy Microsoft Entra ID
Microsoft Entra hybrid joined Intune Windows LAPS policy Microsoft Entra ID or Active Directory, according to the supported design
Active Directory domain joined Windows LAPS Group Policy Windows Server Active Directory
Domain controller; DSRM password management Windows LAPS Group Policy Windows Server Active Directory
Workplace-joined or personal device Intune Windows LAPS is not supported for this scenario Not applicable

Microsoft documents Group Policy and the configuration service provider (CSP) as distinct policy mechanisms. For an Entra-only Windows 11 device, use Intune rather than treating traditional LAPS Group Policy as the normal management path: Windows LAPS policy settings and Intune Windows LAPS overview.

Prerequisites to check first

  • Confirm the join state. Classify each device as Entra joined, hybrid joined, AD domain joined, or workplace joined before choosing a backup directory. A policy can arrive on a device yet fail operationally if the target directory does not fit its join state.
  • Check Windows servicing. Microsoft’s Intune prerequisites currently list Windows 11 22H2 build 22621.1555 or later with KB5025239, and Windows 11 21H2 build 22000.1817 or later with KB5025224. Verify current cumulative updates rather than relying only on the Windows marketing version; Microsoft may update its support requirements. See Microsoft’s current prerequisites.
  • For Intune, enroll the device and assign a policy. Microsoft documents Intune Plan 1 and Microsoft Entra ID Free among the prerequisites for this capability; confirm current tenant licensing and role requirements before deployment.
  • Enable Entra LAPS for Entra-joined devices. In the Microsoft Entra admin center, go to Identity > Devices > Overview > Device settings, set Enable Local Administrator Password Solution (LAPS) to Yes, and save. Hybrid scenarios have different requirements; confirm the chosen backup destination and tenant/device configuration rather than assuming this Entra-only prerequisite applies identically.
  • Plan the account. The built-in Administrator account is the default target. In manual mode, a custom account must already exist; Windows LAPS does not create it. Automatic account management is available starting with Windows 11 24H2.
  • Plan access separately from policy deployment. The permissions needed to configure policy, read metadata, retrieve a clear-text password, and request rotation are not interchangeable.

For feature details and current supported platforms, see Microsoft’s Intune Windows LAPS overview and Windows LAPS CSP documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure Windows LAPS in Intune

  1. Open the Microsoft Intune admin center and go to Endpoint security > Account protection.
  2. Select Create Policy, choose Windows for the platform, and select Local admin password solution (Windows LAPS) as the profile.
  3. Set the backup directory to match the device scenario. For Entra-backed cloud-native devices, choose Microsoft Entra ID. Use AD backup only where the device and organization’s design support it.
  4. Configure the managed account and password lifecycle settings. Begin with a pilot configuration, and separate settings for older Windows releases from 24H2-only features.
  5. Assign the policy to a pilot device group, then review policy status and device-level results before expanding deployment. Microsoft warns that user-group assignments can cause configurations to change as different users sign in, creating account-management conflicts.

Microsoft’s current workflow and setting descriptions are in Create and manage Windows LAPS policies in Intune.

A practical starting configuration

The values below are operational recommendations, not universal Microsoft requirements. Validate them against help-desk procedures and local password policy before broad deployment.

Setting Suggested starting point Qualification
Backup directory Microsoft Entra ID for cloud-native devices; AD for traditional domain devices Must match the supported device and directory design.
Managed account Built-in Administrator initially Use a custom or automatically managed account only with an intentional account plan.
Password age 30 days Operational choice; Entra backup requires at least 7 days.
Password length 20–24 characters where compatible Check the device’s local password policy.
Password complexity 4 on pre-24H2 devices Values 5–8 require Windows 11 24H2 or later.
Password expiration protection Enabled where supported AD-specific setting; not available for Entra backup.
Post-authentication reset delay Choose a short delay compatible with support workflows Balance exposure reduction against disrupting legitimate help-desk work.
Policy assignment Pilot and production device groups Avoid broad user-group assignments for LAPS configuration.

Configure Windows LAPS through Group Policy

Use this route for AD domain-joined computers and domain-controller DSRM password management. The Windows LAPS administrative template is installed with Windows at %windir%PolicyDefinitionsLAPS.admx. In an environment using a Group Policy Central Store, copy the current LAPS ADMX and its language files there manually; Windows Update does not copy them into the Central Store.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.
  1. In Group Policy Management Editor, open Computer Configuration > Policies > Administrative Templates > System > LAPS.
  2. For AD password backup, configure BackupDirectory = 2. The values are 0 for disabled, 1 for Microsoft Entra ID, and 2 for Windows Server Active Directory. If backup is disabled, other LAPS settings are ignored.
  3. Choose the managed account and set password age, length, complexity, and post-authentication behavior. If specifying a custom account in manual mode, create it before applying the policy.
  4. For AD backup, decide whether to enable password encryption, specify the authorized decryption principal, and retain encrypted password history. AD password encryption requires an AD Domain Functional Level of 2016 or later.
  5. For domain controllers, configure DSRM password backup where required. This setting is a Group Policy/domain-controller scenario; the LAPS CSP does not support it.
  6. Delegate read and decryption rights to the appropriate groups, then pilot the GPO and verify that devices are processing the intended policy.

See Microsoft’s Windows LAPS policy settings and Active Directory deployment scenario.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand the settings and version limits

Setting Purpose and scope Documented value or behavior
BackupDirectory Selects where credentials are stored; Entra or AD 0 disabled; 1 Entra ID; 2 AD.
AdministratorAccountName Selects the local account to manage Built-in Administrator is the default.
PasswordAgeDays Maximum password age 1–365 days; default 30. Entra backup requires at least 7 days. Changing the age does not necessarily rotate the current password immediately.
PasswordLength Password length 8–64 characters; default 14.
PasswordComplexity Character-class or newer passphrase-related complexity mode Default 4 (uppercase, lowercase, numbers, and special characters). Values 5–8 require Windows 11 24H2, Windows Server 2025, or later.
PassphraseLength Number of words in a generated passphrase 3–10 words; Windows 11 24H2, Windows Server 2025, or later.
PostAuthenticationResetDelay Delay after password expiration before the configured action Default 24 hours.
PostAuthenticationActions Actions after password expiration Default behavior resets the password and signs out.
PasswordExpirationProtectionEnabled Prevents password expiry from exceeding policy AD setting; default true.
ADPasswordEncryptionEnabled Encrypts passwords backed up to AD AD only; requires Domain Functional Level 2016 or later.
ADPasswordEncryptionPrincipal Specifies who can decrypt AD-stored passwords AD only; defaults to Domain Admins if unspecified.
ADEncryptedPasswordHistorySize Number of encrypted historical AD passwords retained AD only; 0–12.
ADBackupDSRMPassword AD and Group Policy/domain-controller scenario only.
AutomaticAccountManagementEnabled and related automatic-account settings Enables automatic account management and selects or names the target account Windows 11 24H2 and later. Related options include account target, name or prefix, whether to enable the account, and randomized naming.

For exact policy definitions and compatibility, consult Microsoft’s policy settings reference and password and passphrase guidance. If a configured length or complexity conflicts with local password policy, Windows LAPS can fail to generate a compatible password; Microsoft identifies event 10027 as a relevant failure indicator.

Verify that policy processed and a password was backed up

Windows LAPS processes active policy periodically. To request processing immediately on a test device, run this from an elevated PowerShell session:

Rank #3
Invoke-LapsPolicyProcessing

For Microsoft Entra backup, Microsoft identifies event 10029 as a successful password-update event. Also check the Intune device’s policy status and confirm that the device object is enabled and the expected backup destination is configured. For AD deployment, verify the device is domain joined, can reach the domain as needed, and that the required AD permissions and policy are in place.

Microsoft’s Entra deployment guidance is available at Windows LAPS with Microsoft Entra ID.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Retrieve or rotate the managed password

Microsoft Entra-backed credentials

In Intune, open Devices > All devices, select the Windows device, then under Monitor select Local admin password. The page can show the account name and rotation information, and the clear-text password when it is backed up to Microsoft Entra ID. Viewing the password requires the relevant Entra permission, including microsoft.directory/deviceLocalCredentials/password/read, and creates an audit event.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

PowerShell retrieval is also available:

Get-LapsAADPassword -DeviceIds <device-id> -IncludePasswords

Clear-text retrieval requires Microsoft Graph permission DeviceLocalCredential.Read.All; metadata-only access uses DeviceLocalCredential.ReadBasic.All. Use least privilege and grant password-reading access only to administrators who need it. See Get-LapsAADPassword.

AD-backed credentials

The Intune Local admin password page does not display passwords backed up to on-premises AD. Use the Windows LAPS Active Directory tooling and the permissions delegated for that environment, such as Get-LapsADPassword.

Request an early rotation

For an Entra-backed device, use Devices > All devices > [device] > Rotate Local admin password in Intune. The device must be Entra joined or hybrid joined and actively backing up through Windows LAPS to Entra ID. The administrator needs the Intune remote-task permission for rotation, along with the applicable managed-device and organization read permissions. Details are in Microsoft’s rotation action documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

For an AD-managed device, an administrator can request policy processing and use:

Reset-LapsPassword
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common failures

Symptom What to check
Policy appears assigned but no password is backed up Confirm BackupDirectory is not disabled and matches the join state; enable Entra LAPS for Entra-joined devices; confirm the device is supported and updated, enabled in Entra where applicable, and not merely workplace joined. Check whether a higher-precedence CSP policy is active.
Custom account is not managed In manual account-management mode, create and enable the custom account first. Automatic account management requires Windows 11 24H2 or later.
Password cannot be viewed in Intune Confirm the credential is backed up to Entra ID, not AD; confirm the administrator has password-read permission. AD-backed credentials require the AD retrieval method.
Rotate action is missing or unavailable Check corporate device eligibility, Entra or hybrid join, active Entra backup, and the Intune remote-task role permissions for rotation.
Password generation fails Check local password policy compatibility with configured length and complexity; review event 10027. Use separate policies or filters when a setting is only supported on 24H2 and later.
Newer complexity or passphrase setting behaves differently across devices Values 5–8 and passphrase settings require Windows 11 24H2 or later. Do not assume an older release supports those features.

Microsoft’s Intune troubleshooting and requirements reference is the Windows LAPS overview; policy-specific behavior is documented in the policy settings reference.

Prevent policy conflicts and credential loss

Windows LAPS has separate policy roots for CSP, Windows LAPS Group Policy, local configuration, and legacy Microsoft LAPS. The CSP policy root takes precedence over the Windows LAPS Group Policy root. If multiple management systems are configured, Windows LAPS selects the active policy root rather than merging each setting across roots; missing settings in the selected root use defaults. Therefore, an Intune LAPS policy can supersede an existing GPO configuration. Avoid simultaneously managing the same device through Intune, GPO, and legacy Microsoft LAPS unless the transition is deliberately planned.

Protect the Entra device object lifecycle: Microsoft states that deleting a device object also deletes its associated LAPS credential from Entra ID, with no Entra recovery method unless the organization has a separate workflow for retrieving and storing credentials externally. Treat device deletion as a security-sensitive operation, not as a harmless cleanup step. AD deployments should likewise limit credential retrieval and decryption rights to designated groups.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For background on the distinction between the built-in Windows LAPS system and earlier LAPS management, see Microsoft’s Windows LAPS overview and LAPS CSP reference.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$304.99
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.