Back to blog
SecurityPublished on July 18, 20269 min read

Windows LAPS with Intune: Secure the Local Admin

Deploy Windows LAPS through Intune to manage a unique, rotating local administrator password stored securely in Microsoft Entra ID, with no third-party agent.

How many of your Windows PCs share the exact same local administrator password today? In many small businesses the answer is simple: all of them. That single password, often set once during imaging and then never changed, is one of the most dangerous blind spots in a fleet. The day an attacker gets hold of it on just one machine, they effectively hold the key to every machine.

Windows LAPS (Local Administrator Password Solution) answers precisely this problem. Each PC receives a unique local administrator password, generated and rotated automatically, then backed up in encrypted form to Microsoft Entra ID. This article is for IT managers, Intune administrators and MSSPs who want to close that door without deploying a third-party tool or writing a single line of PowerShell.

The problem: a shared secret that becomes a highway

The danger of a common local admin password has a name: lateral movement. An attacker who compromises one PC (through phishing, a booby-trapped macro, or a vulnerability) starts by extracting the credentials stored locally. If the local administrator account carries the same password everywhere, they simply replay that secret from machine to machine, working their way toward servers and privileged accounts.

LAPS breaks this reuse. Because every device holds a different, unpredictable password that nobody knows in advance, a secret stolen from one PC only opens that one PC. The chain that lateral movement relies on is cut clean.

What LAPS delivers in practice

  • A unique, complex password per machine, generated automatically and never reused anywhere else.
  • Regular, automatic rotation on a schedule you set.
  • Encrypted storage of the password in Entra ID, with no local directory or extra server required.
  • Controlled recovery by authorized administrators only, with traceability of who accessed what.
  • Native integration into Windows, driven by Intune, with no third-party agent to install.
A unique, rotating local admin password per PC, kept encrypted in Entra ID.

Set up Windows LAPS through Intune

Deployment happens in two stages that must not be reversed: first prepare Microsoft Entra ID to receive and store the passwords, then deploy the LAPS policy to devices from Intune. Following this order avoids the most common mistake, where PCs try to back up their password while the directory is not yet ready to receive it.

Step 1: enable backup on the Entra ID side

In the Microsoft Entra admin center, open the device settings and enable Windows LAPS password backup. This setting is what allows Entra-joined devices to deposit their secret into the directory. Without it, the policy will apply but no password will ever surface.

Step 2: create and target the policy in Intune

  1. 1Enable LAPS password backup in the Entra ID device settings.
  2. 2In Intune, create an Account protection security policy of type LAPS targeting your Windows PCs.
  3. 3Choose Microsoft Entra ID as the backup directory, then set the managed administrator account, complexity and password length.
  4. 4Set the rotation frequency, for example an automatic rotation every 30 days.
  5. 5Assign the policy to a pilot group, let devices sync, then verify password recovery on the administrator side.

In practice, LAPS can also manage the creation and enablement of the local administrator account it controls, which saves you from preparing that account by hand on each PC. You then confirm that a password actually appears on the device record, in Intune or in Entra, before rolling the deployment out to the rest of the fleet.

The right order: enable backup in Entra, then push the LAPS policy through Intune.

Good practices and common pitfalls

LAPS only adds value if access to the passwords is itself controlled. A password that rotates but is readable by everyone protects nothing. The discipline around recovery matters as much as the technical configuration.

Do

  • Strictly limit who can read LAPS passwords, via the appropriate Entra roles granted to as few people as possible.
  • Pick a rotation neither too long nor too short, consistent with your support habits: too long and an exposed secret stays valid; too short and you multiply friction.
  • After any action that used the password, trigger an immediate rotation to make the secret obsolete at once.
  • Document the setup: LAPS is a control valued in an ISO 27001 audit, notably around privileged access management (A.5.15, A.5.18).
  • Fold LAPS into a broader least-privilege effort: remove standing administrator rights from standard users.

Avoid

  • Deploying the Intune policy before enabling backup in Entra ID.
  • Leaving too many administrators able to read passwords without traceability.
  • Forgetting to rotate the password after a contractor used it during a support action.
  • Treating LAPS as sufficient on its own, when it should accompany the reduction of local rights.
One local admin password per machine, rotated after every use: lateral movement loses its highway.

This least-privilege logic is the point of LAPS. The end goal is for users to work without standing administrator privileges, and for the local admin account, now unique and rotating, to be used only occasionally by support, under control and with traceability. In that way, LAPS turns a historic Windows weak point into a genuinely defensive mechanism.

How AuPoint helps

Getting the Entra-side enablement and the Intune-side policy right, with the correct read permissions, leaves little room for error, but it assumes you know every setting. AuPoint prepares and deploys Windows LAPS cleanly, in plain language and in a few clicks, with no PowerShell. You preview the impact before applying, you keep a break-glass safety account, and every policy stays reversible if needed.

Restrict access, pace the rotation, rotate after use, document for the audit.

FAQ

Does Windows LAPS need a special server or agent?

No. Windows LAPS is built into recent versions of Windows and is driven directly from Intune. When passwords are backed up to Microsoft Entra ID, no domain controller or local directory is required, and there is no third-party agent to install.

Who can read the passwords stored in Entra ID?

Only accounts holding the appropriate Entra roles can recover a LAPS password. It is strongly recommended to reserve this right for a small number of administrators, to track reads, and to trigger a rotation as soon as a password has been viewed and used.

How often should passwords be rotated?

An automatic rotation of around 30 days is a solid starting point for most fleets. Complement it with an immediate manual rotation after any action that required the password, so an exposed secret never stays valid for long.

Ready to close the shared admin password door for good? Connect your Microsoft tenant in a few clicks and deploy Windows LAPS cleanly, with impact preview and reversibility. Start free at aupoint.io.

Secure your tenant in 15 minutes

Free trial