How to Configure Windows LAPS in Microsoft Intune: Complete Step-by-Step Guide

Quick Answer: To configure Windows LAPS in Microsoft Intune, first enable the tenant feature in the Microsoft Entra admin center under Devices > Device settings > Enable Microsoft Entra Local Administrator Password Solution (LAPS). Next, go to the Microsoft Intune admin center, navigate to Endpoint security > Account protection > Create Policy, choose platform Windows, and select profile Local admin password solution (Windows LAPS). Configure the backup directory to Entra ID, define password complexity, enable Automatic Account Management to dynamically provision a dedicated local administrator account (such as ITAdmin), assign the policy to your devices, and trigger client evaluation using Invoke-LapsPolicyProcessing.

Why Modern Windows LAPS Replaced Legacy LAPS

For more than a decade, systems engineers managed endpoint administrator credentials using legacy Microsoft LAPS. That older tool required deploying an external MSI package (AdmPwd.dll), extending the Active Directory schema, and maintaining Group Policy Objects. It did not support cloud-only Microsoft Entra ID joined endpoints without custom scripts, third-party agents, or hybrid domain workarounds.

Modern Windows LAPS is natively integrated into the Windows operating system starting with Windows 10 (20H2, 21H2, 22H2 with the April 2023 cumulative update or later) and Windows 11. It operates through the native OS kernel, requires no MSI installation, and writes encrypted passwords directly to Microsoft Entra ID or on-premises Active Directory.

Feature Legacy Microsoft LAPS Modern Windows LAPS (Intune)
Client Software Requires AdmPwd.dll MSI installer Built directly into Windows OS kernel
Storage Target On-premises Active Directory only Microsoft Entra ID or on-premises Active Directory
Policy Delivery Group Policy Objects (GPO) Microsoft Intune Account Protection CSP / GPO
Account Provisioning Requires manual creation or packaging scripts Native Automatic Account Management creates the account
Post-Authentication Action Not supported (manual resets only) Automatic password reset upon grace period expiry
Dedicated Event Logs Application Log (event source AdmPwd) Dedicated channel: Microsoft-Windows-LAPS/Operational

Prerequisites for Windows LAPS in Microsoft Intune

Before creating your deployment policy in Intune, verify these core prerequisites across your tenant and client estate:

  • Supported OS Editions: Windows 11 (Pro, Enterprise, Education) or Windows 10 (versions 20H2, 21H2, 22H2 with April 11, 2023 cumulative update KB5025221 or later). Windows Home editions are not supported.
  • Device Join State: Devices must be Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra registered (BYOD or Workplace Joined) devices are not supported.
  • Tenant Licensing: Microsoft Intune Plan 1 license (included in Microsoft 365 Business Premium, E3, E5, and EMS E3/E5). Microsoft Entra ID Free or P1/P2.
  • Administrative Roles: Intune Administrator or Endpoint Security Manager to create and assign policies. Cloud Device Administrator or Helpdesk Administrator in Entra ID to retrieve passwords.

Step 1: Enable Windows LAPS in Microsoft Entra ID

Microsoft Entra ID requires an administrative opt-in to accept and store LAPS passwords from managed endpoints. Turning on this tenant setting is the first required step.

  1. Sign in to the Microsoft Entra admin center (entra.microsoft.com).
  2. In the left navigation menu, expand Devices and select All devices.
  3. Under the Manage section, click Device settings.
  4. Locate the setting labeled Enable Microsoft Entra Local Administrator Password Solution (LAPS).
  5. Toggle the switch to Yes.
  6. Click Save at the top of the page.
Microsoft Entra admin center device settings showing Enable Microsoft Entra Local Administrator Password Solution toggle set to Yes
Enabling Microsoft Entra Local Administrator Password Solution in the Entra admin center.

Warning: If you skip this step, client devices receiving the Intune policy will attempt to upload their generated passwords to Entra ID and encounter error code 0x80072EE7 or Event ID 10025 (Failed to discover Entra tenant capabilities).

Step 2: Create the Windows LAPS Policy in Microsoft Intune

Intune manages Windows LAPS through the Endpoint Security Account Protection configuration service provider (CSP).

  1. Sign in to the Microsoft Intune admin center (intune.microsoft.com).
  2. Go to Endpoint security > Account protection.
  3. Click Create Policy at the top of the table.
  4. Set Platform to Windows (or Windows 10 and later).
  5. Set Profile to Local admin password solution (Windows LAPS).
  6. Click Create.
Microsoft Intune Endpoint Security Account Protection create profile wizard selecting Local admin password solution Windows LAPS
Selecting the Windows LAPS profile in the Account Protection policy wizard.

In the Basics tab, provide a descriptive name and enterprise description:

  • Name: TechEUC - Microsoft Windows LAPS
  • Description: Windows LAPS Configuration policy in Microsoft Intune for TechEUC devices.
Microsoft Intune create policy basics tab showing Name TechEUC - Microsoft Windows LAPS and policy description
Configuring policy identification under the Basics tab.

Click Next to proceed to Configuration settings.

Step 3: Configure LAPS Policy Settings and Automatic Account Management

The configuration settings tab defines how passwords are generated, rotated, and backed up. Windows LAPS includes native Automatic Account Management, which can provision a new custom local administrator account automatically on target workstations.

In our lab environment, we configure the policy to manage a custom account named ITAdmin:

Microsoft Intune Windows LAPS configuration settings showing backup to Entra ID 14 days rotation ITAdmin account and automatic account management
Configured Windows LAPS settings with Automatic Account Management for ITAdmin.

Review the purpose of each setting configured in this profile:

Setting Lab Setting Technical Function
Backup Directory Backup the password to Microsoft Entra ID only Directs client endpoints to encrypt and upload password metadata directly to Microsoft Entra ID.
Password Age Days 14 Specifies the rotation interval. The Windows LAPS client will generate a new randomized password every 14 days.
Administrator Account Name ITAdmin Specifies the name of the local account whose password will be managed. Leaving this blank defaults to the built-in Administrator (RID 500).
Password Complexity Large letters + small letters + numbers Enforces high character entropy, preventing dictionary and credential stuffing attacks.
Password Length 8 (or 16 for high security) Configures password length. For production environments, 16 characters is recommended to satisfy CIS and NIST benchmarks.
Post Authentication Actions Reset password upon grace period expiry After an administrator authenticates with the LAPS credential, Windows starts a grace period timer. When the timer expires, the password resets automatically.
Automatic Account Management Enabled The target account will be automatically managed Instructs the Windows LAPS OS client to manage the local account lifecycle directly without third-party scripts.
Automatic Account Management Target Manage a new custom administrator account Windows LAPS automatically creates the local administrator account if it does not already exist on the client endpoint.
Automatic Account Management Enable Account The target account will be enabled Ensures the target administrator account is set to active and unblocked for immediate troubleshooting use.
Automatic Account Management Name Or Prefix ITAdmin Defines the exact account name created and maintained by the Windows LAPS service.

Architecture Benefit of Automatic Account Management: In older Intune deployments, administrators had to deploy a separate PowerShell script or Win32 app to create a custom local administrator account before LAPS could manage it. With Automatic Account Management enabled, Windows LAPS creates the account, adds it to the local Administrators group, enables it, and rotates its password entirely through native operating system calls.

Click Next. On the Scope tags tab, select your required scope tag (or keep Default) and click Next:

Microsoft Intune create profile scope tags tab showing Default scope tag selected
Assigning scope tags to the Windows LAPS policy.

On the Assignments tab, assign the policy to your targeted Windows device group (e.g. All Windows Devices or a pilot group). Complete the wizard on the Review + create tab and click Save.

Step 4: Triggering Policy Sync and Client Evaluation

By default, Intune client devices check in for policy updates every 8 hours. To apply the Windows LAPS policy immediately on a test machine:

  1. On the client endpoint, open Settings > Accounts > Access work or school.
  2. Select the connected tenant account, click Info, and click Sync.
  3. Alternatively, open PowerShell as Administrator and run:
Invoke-LapsPolicyProcessing

The Invoke-LapsPolicyProcessing cmdlet forces the Windows LAPS background engine to query MDM policies, create or locate the target account (ITAdmin), generate an initial password, and write the credential to Microsoft Entra ID.

Step 5: Validating LAPS Policy on the Client Device

Before checking administrative web consoles, verify that the Windows endpoint processed the policy successfully using local diagnostic tools.

1. Inspecting the Windows Registry

When Intune applies the Account Protection policy via Policy CSP, settings are written directly to the Windows Registry under:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\LAPS

Windows Registry Editor showing HKEY_LOCAL_MACHINE SOFTWARE Microsoft Policies LAPS with AdministratorAccountName ITAdmin and AutomaticAccountManagement registry keys
Registry Editor displaying applied Windows LAPS CSP values under HKLM\SOFTWARE\Microsoft\Policies\LAPS.

You can also query this key via PowerShell to automate deployment validation across endpoints:

Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Policies\LAPS"

The registry confirms that AdministratorAccountName is set to ITAdmin, BackupDirectory is set to 1 (Microsoft Entra ID), PasswordAgeDays is set to 14 (hex 0xe), PasswordLength is set to 8, and AutomaticAccountManagementEnabled is active.

2. Checking the Dedicated Event Viewer Channel

Modern Windows LAPS writes detailed processing diagnostics to its dedicated Windows Event Log channel:

Applications and Services Logs > Microsoft > Windows > LAPS > Operational

Windows Event Viewer displaying Microsoft-Windows-LAPS Operational log with Event ID 10022 showing policy source CSP and ITAdmin configuration
Event ID 10022 in Event Viewer confirming the applied LAPS CSP policy parameters.

As captured in Event ID 10022 on the client, the operating system verifies every applied parameter:

The current LAPS policy is configured as follows:

Policy source: CSP
Backup directory: Azure Active Directory
Local administrator account name: ITAdmin
Password age in days: 14
Password complexity: 3
Password length: 8
Post authentication grace period (hours): 24
Post authentication actions: 0x1
Automatic account management enabled: 1
Automatic account management: Target: CustomAdminAccount
Automatic account management: Name or name prefix: ITAdmin
Automatic account management: Account enabled: 1
Automatic account management: Randomize name: 0

Key Windows LAPS Event IDs

Event ID Type Operational Meaning
10003 Information LAPS policy processing has started.
10004 Information LAPS policy processing completed successfully.
10005 Error LAPS policy processing failed. Inspect the HRESULT code in the event body.
10013 Error Target local administrator account was not found on the device.
10022 Information Current policy parameters evaluated by the endpoint engine.
10025 Error Failed to discover Entra ID LAPS capabilities. Check tenant toggle or network connectivity.
10029 Information Local administrator password successfully backed up to Microsoft Entra ID.

Step 6: Retrieving the Local Administrator Password

Once the endpoint logs Event ID 10029, administrators can retrieve the cleartext password using three separate methods.

Method 1: In the Microsoft Intune Admin Center

  1. Go to Devices > Windows > select your target device (such as TechEUC-1).
  2. In the device sub-menu under Monitor, click Local admin password.
  3. Click Show local administrator password.
Microsoft Intune device monitor page for TechEUC-1 showing Show local administrator password option and rotation schedule
Accessing Local admin password under the device monitor menu for TechEUC-1.

Intune opens a flyout pane displaying the managed account name (ITAdmin), Security ID (SID), cleartext password, last rotation timestamp, and the next scheduled rotation date:

Microsoft Intune flyout pane showing Account name ITAdmin Security ID and local administrator password
Intune flyout blade displaying ITAdmin credential details and rotation timestamps.

Method 2: In the Microsoft Entra Admin Center

  1. Sign in to the Microsoft Entra admin center (entra.microsoft.com).
  2. Navigate to Devices > All devices.
  3. Under the Manage section in the left menu, click Local administrator password recovery.
  4. Find your device (e.g. TechEUC-1, TechEUC-2, or TechEUC-3) in the inventory table.
  5. Click Show local administrator password.
Microsoft Entra admin center Local administrator password recovery page showing TechEUC-1 TechEUC-2 and TechEUC-3 inventory table
Centralized Local administrator password recovery table in Microsoft Entra admin center.

Method 3: Using Microsoft Graph PowerShell

Helpdesk and automation teams can retrieve passwords programmatically using the Microsoft Graph PowerShell SDK:

Connect-MgGraph -Scopes "DeviceLocalCredential.Read.All"
$device = Get-MgDevice -Filter "displayName eq 'TechEUC-1'"
Get-MgDeviceLocalCredential -DeviceId $device.Id | Select-Object -ExpandProperty Credentials

Security Auditing: Every time an administrator views a LAPS password in Intune, Entra ID, or through PowerShell, Microsoft Entra ID creates an entry in the Audit logs with activity Read MS-Mcs-AdmPwd (LAPS) password, recording the user principal name, device ID, and timestamp.

Step 7: On-Demand Remote Password Rotation

If a technician finishes a troubleshooting session and you want to rotate the credential immediately without waiting for the 14-day cycle or the post-authentication timer:

  1. In the Microsoft Intune admin center, navigate to Devices > Windows > select your device.
  2. In the top toolbar, click the three horizontal dots (…) to reveal more remote actions.
  3. Click Rotate local admin password.
  4. Confirm the prompt. Intune sends an immediate push notification to the client endpoint to generate a new password and sync it to Entra ID.

Permissions Required to Access Local Admin Passwords

To follow the principle of least privilege, do not assign Global Administrator roles just to read LAPS passwords. Microsoft Entra ID and Intune support specific granular permissions:

  • Intune RBAC: Users need the Managed Devices > Read and Managed Devices > Query Local Administrator Password permissions. This is built into the Endpoint Security Manager and Helpdesk Operator roles.
  • Entra ID Built-in Roles: Cloud Device Administrator and Helpdesk Administrator have native read access to recover LAPS passwords.
  • Entra ID Custom Role: You can create a scoped custom role with only the microsoft.directory/deviceLocalCredentials/password/read permission for tier-1 support technicians.

Summary Verification Checklist

Stage Check Item Expected Production Result
Tenant Entra ID Device Settings Enable Microsoft Entra LAPS set to Yes.
Intune Account Protection Profile TechEUC - Microsoft Windows LAPS deployed with ITAdmin target account.
Client Sync PowerShell verification Invoke-LapsPolicyProcessing completes without error.
Registry HKLM Policies LAPS Keys exist for BackupDirectory, PasswordAgeDays, AdministratorAccountName, and AutomaticAccountManagement.
Event Viewer LAPS Operational Channel Event ID 10022 (policy configuration) and Event ID 10029 (Entra backup) logged.
Intune Recovery Device Monitor Blade Show local administrator password displays cleartext ITAdmin password and rotation schedule.
Entra Recovery LAPS Recovery Blade Centralized table lists devices (TechEUC-1, TechEUC-2, TechEUC-3) with recovery actions.
Audit Log Entra ID Audit Logs Audit entry logged for Read MS-Mcs-AdmPwd (LAPS) password.

Need Enterprise Endpoint Security Engineering?

Implementing zero-trust endpoint access and securing local administrator privileges across thousands of Windows workstations requires disciplined policy design. If your organization is transitioning from legacy GPO solutions to modern Microsoft Intune architecture, TechEUC provides specialized enterprise infrastructure engineering. Reach out through our Contact Page to collaborate on your endpoint security initiatives.

TechEUC - Atoofa Shaikh
FIVERR PRO VERIFIED 12+ YRS EXPERIENCE

Atoofa Shaikh

Senior Microsoft 365, EUC & Cloud Endpoint Architect

Need custom Win32 App Packaging, PowerShell Automation, Zero-Touch Intune Autopilot, or SCCM Co-Management for your enterprise or MSP? I specialize in production-grade deployment architectures with zero downtime.