Skip to content

Deploying LAPS

Deploying LAPS with GPO

Local Administrator Password Solution (LAPS) is a critical tool for securely managing local administrator passwords on domain-joined computers. When deploying LAPS via Group Policy Preferences (GPP), administrators can centrally configure password storage in Active Directory (AD) and enforce security policies. This section outlines the steps to deploy LAPS using GPO and configure password storage.


Prerequisites

Before deploying LAPS, ensure:
- Windows Server 2016 or later is installed (LAPS is not available in earlier versions).
- The domain is functional and the AD schema is extended to support LAPS attributes (automatically handled during LAPS installation).
- Group Policy Management Console (GPMC) is available for configuring policies.


Step 1: Install LAPS on Domain Controllers

LAPS must be installed on domain controllers (DCs) to manage password storage.

Install LAPS via Server Manager:
1. Open Server Manager.
2. Navigate to Add Roles and Features.
3. Select the target domain controller and proceed through the wizard.
4. Under Server Roles, select Local Administrator Password Solution (LAPS).
5. Complete the installation to extend the AD schema.


Step 2: Configure LAPS via Group Policy Preferences

Create a GPO linked to the OU containing target computers.

2.1 Enable LAPS for Computers

  1. Open Group Policy Management Editor (gpedit.msc).
  2. Navigate to:
    Computer Configuration > Policies > Administrative Templates > System > Local Account Password Solution.
  3. Enable "Enable Local Account Password Solution".

2.2 Configure Password Storage Attributes

Use the LAPS GPO template to define password storage settings:
1. Open Group Policy Management Editor.
2. Navigate to:
Computer Configuration > Policies > Administrative Templates > System > Local Account Password Solution.
3. Configure the following settings:
- Enable password storage in the computer account: Enabled
- Password complexity requirements: Enabled

2.3 Enforce Password Complexity

  1. Navigate to:
    Computer Configuration > Policies > Windows Settings > Security Settings > Password Policy.
  2. Configure the following settings:
  3. Minimum password length: 12
  4. Password must meet complexity requirements: Enabled
  5. Enforce password history: 24
  6. Maximum password age: 30

Step 3: Ensure Client Computers Have LAPS Client

LAPS clients are not automatically installed on domain-joined computers. You must deploy the LAPS client via GPP or a script.

Option 1: Use GPP to Deploy LAPS Client
1. Open Group Policy Management Editor.
2. Navigate to:
Computer Configuration > Preferences > Windows Settings > Scripts (Logon/Logoff).
3. Add a Logon Script to install the LAPS client:

@echo off
msiexec.exe /i "LAPS_Client.msi" /quiet

Note: Replace LAPS_Client.msi with the actual installer path.

Option 2: Use Microsoft Endpoint Configuration Manager (MECM) for silent installation.


Step 4: Verify LAPS Functionality

  1. Use the LAPS PowerShell module to retrieve passwords:
    Get-ADComputer -Filter * -Property * | Select-Object Name, ms-DS-MachineAccountPassword
    
  2. Check if the password is stored in the computer account’s ms-DS-MachineAccountPassword attribute.

Key takeaways

  • Install LAPS on all domain controllers to enable password management.
  • Use the LAPS GPO template to configure password storage attributes and enforce complexity rules.
  • Ensure client computers have the LAPS client installed to retrieve passwords.
  • Verify password storage via PowerShell or LDAP tools to confirm successful deployment.
  • Regularly audit AD attributes to ensure LAPS passwords are securely managed.