Quick Answer: To configure Windows LAPS in Microsoft Intune, first enable the tenant feature in the Microsoft Entra admin center under Devices > Device settings > Enable Microsoft Entra Local Administrator Password Solution (LAPS). Next, go to the Microsoft Intune admin center, navigate to Endpoint security > Account protection > Create Policy, choose platform Windows, and select profile Local admin password solution (Windows LAPS). Configure the backup directory to Entra ID, define password complexity, enable Automatic Account Management to dynamically provision a dedicated local administrator account (such as ITAdmin), assign the policy to your devices, and trigger client evaluation using Invoke-LapsPolicyProcessing.
Why Modern Windows LAPS Replaced Legacy LAPS
For more than a decade, systems engineers managed endpoint administrator credentials using legacy Microsoft LAPS. That older tool required deploying an external MSI package (AdmPwd.dll), extending the Active Directory schema, and maintaining Group Policy Objects. It did not support cloud-only Microsoft Entra ID joined endpoints without custom scripts, third-party agents, or hybrid domain workarounds.
Modern Windows LAPS is natively integrated into the Windows operating system starting with Windows 10 (20H2, 21H2, 22H2 with the April 2023 cumulative update or later) and Windows 11. It operates through the native OS kernel, requires no MSI installation, and writes encrypted passwords directly to Microsoft Entra ID or on-premises Active Directory.
Feature
Legacy Microsoft LAPS
Modern Windows LAPS (Intune)
Client Software
Requires AdmPwd.dll MSI installer
Built directly into Windows OS kernel
Storage Target
On-premises Active Directory only
Microsoft Entra ID or on-premises Active Directory
Policy Delivery
Group Policy Objects (GPO)
Microsoft Intune Account Protection CSP / GPO
Account Provisioning
Requires manual creation or packaging scripts
Native Automatic Account Management creates the account
Prerequisites for Windows LAPS in Microsoft Intune
Before creating your deployment policy in Intune, verify these core prerequisites across your tenant and client estate:
Supported OS Editions: Windows 11 (Pro, Enterprise, Education) or Windows 10 (versions 20H2, 21H2, 22H2 with April 11, 2023 cumulative update KB5025221 or later). Windows Home editions are not supported.
Device Join State: Devices must be Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra registered (BYOD or Workplace Joined) devices are not supported.
Tenant Licensing: Microsoft Intune Plan 1 license (included in Microsoft 365 Business Premium, E3, E5, and EMS E3/E5). Microsoft Entra ID Free or P1/P2.
Administrative Roles: Intune Administrator or Endpoint Security Manager to create and assign policies. Cloud Device Administrator or Helpdesk Administrator in Entra ID to retrieve passwords.
Step 1: Enable Windows LAPS in Microsoft Entra ID
Microsoft Entra ID requires an administrative opt-in to accept and store LAPS passwords from managed endpoints. Turning on this tenant setting is the first required step.
Sign in to the Microsoft Entra admin center (entra.microsoft.com).
In the left navigation menu, expand Devices and select All devices.
Under the Manage section, click Device settings.
Locate the setting labeled Enable Microsoft Entra Local Administrator Password Solution (LAPS).
Toggle the switch to Yes.
Click Save at the top of the page.
Enabling Microsoft Entra Local Administrator Password Solution in the Entra admin center.
Warning: If you skip this step, client devices receiving the Intune policy will attempt to upload their generated passwords to Entra ID and encounter error code 0x80072EE7 or Event ID 10025 (Failed to discover Entra tenant capabilities).
Step 2: Create the Windows LAPS Policy in Microsoft Intune
Intune manages Windows LAPS through the Endpoint Security Account Protection configuration service provider (CSP).
Sign in to the Microsoft Intune admin center (intune.microsoft.com).
Go to Endpoint security > Account protection.
Click Create Policy at the top of the table.
Set Platform to Windows (or Windows 10 and later).
Set Profile to Local admin password solution (Windows LAPS).
Click Create.
Selecting the Windows LAPS profile in the Account Protection policy wizard.
In the Basics tab, provide a descriptive name and enterprise description:
Name:TechEUC - Microsoft Windows LAPS
Description:Windows LAPS Configuration policy in Microsoft Intune for TechEUC devices.
Configuring policy identification under the Basics tab.
Click Next to proceed to Configuration settings.
Step 3: Configure LAPS Policy Settings and Automatic Account Management
The configuration settings tab defines how passwords are generated, rotated, and backed up. Windows LAPS includes native Automatic Account Management, which can provision a new custom local administrator account automatically on target workstations.
In our lab environment, we configure the policy to manage a custom account named ITAdmin:
Configured Windows LAPS settings with Automatic Account Management for ITAdmin.
Review the purpose of each setting configured in this profile:
Setting
Lab Setting
Technical Function
Backup Directory
Backup the password to Microsoft Entra ID only
Directs client endpoints to encrypt and upload password metadata directly to Microsoft Entra ID.
Password Age Days
14
Specifies the rotation interval. The Windows LAPS client will generate a new randomized password every 14 days.
Administrator Account Name
ITAdmin
Specifies the name of the local account whose password will be managed. Leaving this blank defaults to the built-in Administrator (RID 500).
Password Complexity
Large letters + small letters + numbers
Enforces high character entropy, preventing dictionary and credential stuffing attacks.
Password Length
8 (or 16 for high security)
Configures password length. For production environments, 16 characters is recommended to satisfy CIS and NIST benchmarks.
Post Authentication Actions
Reset password upon grace period expiry
After an administrator authenticates with the LAPS credential, Windows starts a grace period timer. When the timer expires, the password resets automatically.
Automatic Account Management Enabled
The target account will be automatically managed
Instructs the Windows LAPS OS client to manage the local account lifecycle directly without third-party scripts.
Automatic Account Management Target
Manage a new custom administrator account
Windows LAPS automatically creates the local administrator account if it does not already exist on the client endpoint.
Automatic Account Management Enable Account
The target account will be enabled
Ensures the target administrator account is set to active and unblocked for immediate troubleshooting use.
Automatic Account Management Name Or Prefix
ITAdmin
Defines the exact account name created and maintained by the Windows LAPS service.
Architecture Benefit of Automatic Account Management: In older Intune deployments, administrators had to deploy a separate PowerShell script or Win32 app to create a custom local administrator account before LAPS could manage it. With Automatic Account Management enabled, Windows LAPS creates the account, adds it to the local Administrators group, enables it, and rotates its password entirely through native operating system calls.
Click Next. On the Scope tags tab, select your required scope tag (or keep Default) and click Next:
Assigning scope tags to the Windows LAPS policy.
On the Assignments tab, assign the policy to your targeted Windows device group (e.g. All Windows Devices or a pilot group). Complete the wizard on the Review + create tab and click Save.
Step 4: Triggering Policy Sync and Client Evaluation
By default, Intune client devices check in for policy updates every 8 hours. To apply the Windows LAPS policy immediately on a test machine:
On the client endpoint, open Settings > Accounts > Access work or school.
Select the connected tenant account, click Info, and click Sync.
Alternatively, open PowerShell as Administrator and run:
Invoke-LapsPolicyProcessing
The Invoke-LapsPolicyProcessing cmdlet forces the Windows LAPS background engine to query MDM policies, create or locate the target account (ITAdmin), generate an initial password, and write the credential to Microsoft Entra ID.
Step 5: Validating LAPS Policy on the Client Device
Before checking administrative web consoles, verify that the Windows endpoint processed the policy successfully using local diagnostic tools.
1. Inspecting the Windows Registry
When Intune applies the Account Protection policy via Policy CSP, settings are written directly to the Windows Registry under:
The registry confirms that AdministratorAccountName is set to ITAdmin, BackupDirectory is set to 1 (Microsoft Entra ID), PasswordAgeDays is set to 14 (hex 0xe), PasswordLength is set to 8, and AutomaticAccountManagementEnabled is active.
2. Checking the Dedicated Event Viewer Channel
Modern Windows LAPS writes detailed processing diagnostics to its dedicated Windows Event Log channel:
Applications and Services Logs > Microsoft > Windows > LAPS > Operational
Event ID 10022 in Event Viewer confirming the applied LAPS CSP policy parameters.
As captured in Event ID 10022 on the client, the operating system verifies every applied parameter:
The current LAPS policy is configured as follows:
Policy source: CSP
Backup directory: Azure Active Directory
Local administrator account name: ITAdmin
Password age in days: 14
Password complexity: 3
Password length: 8
Post authentication grace period (hours): 24
Post authentication actions: 0x1
Automatic account management enabled: 1
Automatic account management: Target: CustomAdminAccount
Automatic account management: Name or name prefix: ITAdmin
Automatic account management: Account enabled: 1
Automatic account management: Randomize name: 0
Key Windows LAPS Event IDs
Event ID
Type
Operational Meaning
10003
Information
LAPS policy processing has started.
10004
Information
LAPS policy processing completed successfully.
10005
Error
LAPS policy processing failed. Inspect the HRESULT code in the event body.
10013
Error
Target local administrator account was not found on the device.
10022
Information
Current policy parameters evaluated by the endpoint engine.
10025
Error
Failed to discover Entra ID LAPS capabilities. Check tenant toggle or network connectivity.
10029
Information
Local administrator password successfully backed up to Microsoft Entra ID.
Step 6: Retrieving the Local Administrator Password
Once the endpoint logs Event ID 10029, administrators can retrieve the cleartext password using three separate methods.
Method 1: In the Microsoft Intune Admin Center
Go to Devices > Windows > select your target device (such as TechEUC-1).
In the device sub-menu under Monitor, click Local admin password.
Click Show local administrator password.
Accessing Local admin password under the device monitor menu for TechEUC-1.
Intune opens a flyout pane displaying the managed account name (ITAdmin), Security ID (SID), cleartext password, last rotation timestamp, and the next scheduled rotation date:
Intune flyout blade displaying ITAdmin credential details and rotation timestamps.
Method 2: In the Microsoft Entra Admin Center
Sign in to the Microsoft Entra admin center (entra.microsoft.com).
Navigate to Devices > All devices.
Under the Manage section in the left menu, click Local administrator password recovery.
Find your device (e.g. TechEUC-1, TechEUC-2, or TechEUC-3) in the inventory table.
Click Show local administrator password.
Centralized Local administrator password recovery table in Microsoft Entra admin center.
Method 3: Using Microsoft Graph PowerShell
Helpdesk and automation teams can retrieve passwords programmatically using the Microsoft Graph PowerShell SDK:
Security Auditing: Every time an administrator views a LAPS password in Intune, Entra ID, or through PowerShell, Microsoft Entra ID creates an entry in the Audit logs with activity Read MS-Mcs-AdmPwd (LAPS) password, recording the user principal name, device ID, and timestamp.
Step 7: On-Demand Remote Password Rotation
If a technician finishes a troubleshooting session and you want to rotate the credential immediately without waiting for the 14-day cycle or the post-authentication timer:
In the Microsoft Intune admin center, navigate to Devices > Windows > select your device.
In the top toolbar, click the three horizontal dots (…) to reveal more remote actions.
Click Rotate local admin password.
Confirm the prompt. Intune sends an immediate push notification to the client endpoint to generate a new password and sync it to Entra ID.
Permissions Required to Access Local Admin Passwords
To follow the principle of least privilege, do not assign Global Administrator roles just to read LAPS passwords. Microsoft Entra ID and Intune support specific granular permissions:
Intune RBAC: Users need the Managed Devices > Read and Managed Devices > Query Local Administrator Password permissions. This is built into the Endpoint Security Manager and Helpdesk Operator roles.
Entra ID Built-in Roles:Cloud Device Administrator and Helpdesk Administrator have native read access to recover LAPS passwords.
Entra ID Custom Role: You can create a scoped custom role with only the microsoft.directory/deviceLocalCredentials/password/read permission for tier-1 support technicians.
Summary Verification Checklist
Stage
Check Item
Expected Production Result
Tenant
Entra ID Device Settings
Enable Microsoft Entra LAPS set to Yes.
Intune
Account Protection Profile
TechEUC - Microsoft Windows LAPS deployed with ITAdmin target account.
Client Sync
PowerShell verification
Invoke-LapsPolicyProcessing completes without error.
Registry
HKLM Policies LAPS
Keys exist for BackupDirectory, PasswordAgeDays, AdministratorAccountName, and AutomaticAccountManagement.
Event Viewer
LAPS Operational Channel
Event ID 10022 (policy configuration) and Event ID 10029 (Entra backup) logged.
Intune Recovery
Device Monitor Blade
Show local administrator password displays cleartext ITAdmin password and rotation schedule.
Entra Recovery
LAPS Recovery Blade
Centralized table lists devices (TechEUC-1, TechEUC-2, TechEUC-3) with recovery actions.
Audit Log
Entra ID Audit Logs
Audit entry logged for Read MS-Mcs-AdmPwd (LAPS) password.
Need Enterprise Endpoint Security Engineering?
Implementing zero-trust endpoint access and securing local administrator privileges across thousands of Windows workstations requires disciplined policy design. If your organization is transitioning from legacy GPO solutions to modern Microsoft Intune architecture, TechEUC provides specialized enterprise infrastructure engineering. Reach out through our Contact Page to collaborate on your endpoint security initiatives.
FIVERR PRO VERIFIED12+ YRS EXPERIENCE
Atoofa Shaikh
Senior Microsoft 365, EUC & Cloud Endpoint Architect
Need custom Win32 App Packaging, PowerShell Automation, Zero-Touch Intune Autopilot, or SCCM Co-Management for your enterprise or MSP? I specialize in production-grade deployment architectures with zero downtime.
How to Configure Windows LAPS in Microsoft Intune: Complete Step-by-Step Guide
Table of content
Quick Answer: To configure Windows LAPS in Microsoft Intune, first enable the tenant feature in the Microsoft Entra admin center under Devices > Device settings > Enable Microsoft Entra Local Administrator Password Solution (LAPS). Next, go to the Microsoft Intune admin center, navigate to Endpoint security > Account protection > Create Policy, choose platform Windows, and select profile Local admin password solution (Windows LAPS). Configure the backup directory to Entra ID, define password complexity, enable Automatic Account Management to dynamically provision a dedicated local administrator account (such as
ITAdmin), assign the policy to your devices, and trigger client evaluation usingInvoke-LapsPolicyProcessing.Why Modern Windows LAPS Replaced Legacy LAPS
For more than a decade, systems engineers managed endpoint administrator credentials using legacy Microsoft LAPS. That older tool required deploying an external MSI package (AdmPwd.dll), extending the Active Directory schema, and maintaining Group Policy Objects. It did not support cloud-only Microsoft Entra ID joined endpoints without custom scripts, third-party agents, or hybrid domain workarounds.
Modern Windows LAPS is natively integrated into the Windows operating system starting with Windows 10 (20H2, 21H2, 22H2 with the April 2023 cumulative update or later) and Windows 11. It operates through the native OS kernel, requires no MSI installation, and writes encrypted passwords directly to Microsoft Entra ID or on-premises Active Directory.
Microsoft-Windows-LAPS/OperationalPrerequisites for Windows LAPS in Microsoft Intune
Before creating your deployment policy in Intune, verify these core prerequisites across your tenant and client estate:
Step 1: Enable Windows LAPS in Microsoft Entra ID
Microsoft Entra ID requires an administrative opt-in to accept and store LAPS passwords from managed endpoints. Turning on this tenant setting is the first required step.
Warning: If you skip this step, client devices receiving the Intune policy will attempt to upload their generated passwords to Entra ID and encounter error code
0x80072EE7or Event ID10025(Failed to discover Entra tenant capabilities).Step 2: Create the Windows LAPS Policy in Microsoft Intune
Intune manages Windows LAPS through the Endpoint Security Account Protection configuration service provider (CSP).
In the Basics tab, provide a descriptive name and enterprise description:
TechEUC - Microsoft Windows LAPSWindows LAPS Configuration policy in Microsoft Intune for TechEUC devices.Click Next to proceed to Configuration settings.
Step 3: Configure LAPS Policy Settings and Automatic Account Management
The configuration settings tab defines how passwords are generated, rotated, and backed up. Windows LAPS includes native Automatic Account Management, which can provision a new custom local administrator account automatically on target workstations.
In our lab environment, we configure the policy to manage a custom account named
ITAdmin:Review the purpose of each setting configured in this profile:
Architecture Benefit of Automatic Account Management: In older Intune deployments, administrators had to deploy a separate PowerShell script or Win32 app to create a custom local administrator account before LAPS could manage it. With Automatic Account Management enabled, Windows LAPS creates the account, adds it to the local Administrators group, enables it, and rotates its password entirely through native operating system calls.
Click Next. On the Scope tags tab, select your required scope tag (or keep Default) and click Next:
On the Assignments tab, assign the policy to your targeted Windows device group (e.g.
All Windows Devicesor a pilot group). Complete the wizard on the Review + create tab and click Save.Step 4: Triggering Policy Sync and Client Evaluation
By default, Intune client devices check in for policy updates every 8 hours. To apply the Windows LAPS policy immediately on a test machine:
The
Invoke-LapsPolicyProcessingcmdlet forces the Windows LAPS background engine to query MDM policies, create or locate the target account (ITAdmin), generate an initial password, and write the credential to Microsoft Entra ID.Step 5: Validating LAPS Policy on the Client Device
Before checking administrative web consoles, verify that the Windows endpoint processed the policy successfully using local diagnostic tools.
1. Inspecting the Windows Registry
When Intune applies the Account Protection policy via Policy CSP, settings are written directly to the Windows Registry under:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\LAPSYou can also query this key via PowerShell to automate deployment validation across endpoints:
The registry confirms that
AdministratorAccountNameis set toITAdmin,BackupDirectoryis set to1(Microsoft Entra ID),PasswordAgeDaysis set to14(hex0xe),PasswordLengthis set to8, andAutomaticAccountManagementEnabledis active.2. Checking the Dedicated Event Viewer Channel
Modern Windows LAPS writes detailed processing diagnostics to its dedicated Windows Event Log channel:
Applications and Services Logs > Microsoft > Windows > LAPS > OperationalAs captured in Event ID 10022 on the client, the operating system verifies every applied parameter:
Key Windows LAPS Event IDs
Step 6: Retrieving the Local Administrator Password
Once the endpoint logs Event ID 10029, administrators can retrieve the cleartext password using three separate methods.
Method 1: In the Microsoft Intune Admin Center
TechEUC-1).Intune opens a flyout pane displaying the managed account name (
ITAdmin), Security ID (SID), cleartext password, last rotation timestamp, and the next scheduled rotation date:Method 2: In the Microsoft Entra Admin Center
TechEUC-1,TechEUC-2, orTechEUC-3) in the inventory table.Method 3: Using Microsoft Graph PowerShell
Helpdesk and automation teams can retrieve passwords programmatically using the Microsoft Graph PowerShell SDK:
Security Auditing: Every time an administrator views a LAPS password in Intune, Entra ID, or through PowerShell, Microsoft Entra ID creates an entry in the Audit logs with activity
Read MS-Mcs-AdmPwd (LAPS) password, recording the user principal name, device ID, and timestamp.Step 7: On-Demand Remote Password Rotation
If a technician finishes a troubleshooting session and you want to rotate the credential immediately without waiting for the 14-day cycle or the post-authentication timer:
Permissions Required to Access Local Admin Passwords
To follow the principle of least privilege, do not assign Global Administrator roles just to read LAPS passwords. Microsoft Entra ID and Intune support specific granular permissions:
microsoft.directory/deviceLocalCredentials/password/readpermission for tier-1 support technicians.Summary Verification Checklist
TechEUC - Microsoft Windows LAPSdeployed withITAdmintarget account.Invoke-LapsPolicyProcessingcompletes without error.BackupDirectory,PasswordAgeDays,AdministratorAccountName, andAutomaticAccountManagement.ITAdminpassword and rotation schedule.TechEUC-1,TechEUC-2,TechEUC-3) with recovery actions.Read MS-Mcs-AdmPwd (LAPS) password.Need Enterprise Endpoint Security Engineering?
Implementing zero-trust endpoint access and securing local administrator privileges across thousands of Windows workstations requires disciplined policy design. If your organization is transitioning from legacy GPO solutions to modern Microsoft Intune architecture, TechEUC provides specialized enterprise infrastructure engineering. Reach out through our Contact Page to collaborate on your endpoint security initiatives.
Atoofa Shaikh
Senior Microsoft 365, EUC & Cloud Endpoint Architect
Need custom Win32 App Packaging, PowerShell Automation, Zero-Touch Intune Autopilot, or SCCM Co-Management for your enterprise or MSP? I specialize in production-grade deployment architectures with zero downtime.
Table of content
Subscribe to Blog
Signup to our weekly newsletter
category
Connect with Us
Recommended Posts
How to Configure Windows LAPS in Microsoft Intune: Complete Step-by-Step Guide
How to Fix Intune Error 0x87D1041C: App Not Detected After Installation [Complete Runbook]
How to Set Up Windows Autopilot with Microsoft Intune (Production & Lab Guide)