{"id":352,"date":"2023-05-10T10:16:38","date_gmt":"2023-05-10T08:16:38","guid":{"rendered":"https:\/\/blog.bardalen.no\/?page_id=352"},"modified":"2023-05-10T10:16:39","modified_gmt":"2023-05-10T08:16:39","slug":"enabling-and-using-windows-laps","status":"publish","type":"page","link":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/","title":{"rendered":"Enabling and using Windows LAPS"},"content":{"rendered":"\n<p>Windows LAPS just recently released to Public Preview. No no, not the old one (legacy Microsoft LAPS: <a href=\"https:\/\/www.microsoft.com\/download\/details.aspx?id=46899\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.microsoft.com\/download\/details.aspx?id=46899<\/a>). The NEW LAPS. LAPS is an acronym for Local Administrator Password Solution. On Windows-machines there is by default this almighty admin-account that gives you local administrative access to that computer. This can be used in case of emergency where other means of authentication isn\u2019t available, e.g. lost contact with domain controller. But it can also be used for malicious purposes. There are several techniques where passwords can be used to take control over computers. Because managing passwords for every computer can be very tedious, even in small businesses this is often not prioritized. So what do we do? Yeah, use the same password on all the machines and close our eyes. Even though we know this is not very secure. How can you and I avoid this?<\/p>\n\n\n\n<p>The idea is not new but there hasn\u2019t been a good solution for Azure AD-joined machines to handle this. Until now. Windows LAPS takes care of the orchestration of all your machines\u2019 local admin account, rotates the password, and stores it safely for you. And the best thing: it\u2019s free! Let me show you how to set things up.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">But what scenarios are supported?<\/h2>\n\n\n\n<p>The key here is where your devices are JOINED. If your devices are joined to Azure AD as cloud only devices and managed via Intune, you deploy LAPS via Intune. This will not work if you are using your home computer or any private device that are only Workplace Joined or registered only. It must be enrolled and joined for this solution to work.<\/p>\n\n\n\n<p>Prerequisites for the OS are Windows 10 or 11(H2), and Windows Server 2019 or 2022. Additionally, they need the April 2023 update for this to work. This update includes the functionality to enable support for Windows LAPS.<\/p>\n\n\n\n<p>If you have a hybrid environment, you are joined to the traditional Active Directory and registered to Azure AD. Azure AD Connect will sync out your device object to Azure AD and AD will make your computer aware of Azure AD and tells it to register there as well. In this scenario you can choose where you want to store the passwords. You COULD use your local AD for this, but the preferred way is clearly Azure AD. Then it will also support cloud only devices and it\u2019s already setup for the day you remove the hybrid connection and goes all cloud.<\/p>\n\n\n\n<p>In cases where your devices have no concept of Azure AD (Like when there is just a local AD or your machines are running an older version of Windows) you obviously can\u2019t store your passwords in Azure AD. You need to rely on your local Active Directory for that.<\/p>\n\n\n\n<p>If you are going the route of using Active Directory, I can only point you to this Microsoft Docs describing that scenario as I\u2019m not going into it here. This involves e.g. updating the Active Directory Schema, so it\u2019s another game: <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-scenarios-windows-server-active-directory\">https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-scenarios-windows-server-active-directory<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Turn it on!<\/h2>\n\n\n\n<p>How you turn this on depends on your scenario described earlier. In this guide I will only show you how to deploy it in Azure AD. If you need to deploy using GPO, go to Microsoft Docs here to read up on it: <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-management-policy-settings\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-management-policy-settings<\/a><\/p>\n\n\n\n<p>So\u2026 Firstly, log in with an admin account to Microsoft Entra. Se under <strong>\u201cDevices\u201d<\/strong>, <strong>\u201cAll devices\u201d<\/strong> and <strong>\u201cDevice settings\u201d<\/strong>. Scroll down to Enable Azure AD Local Administrator Password Solution (LAPS) (Preview). Make sure you change from <strong>\u201cNo\u201d<\/strong> to <strong>\u201cYes\u201d<\/strong>. Click <strong>\u201cSave\u201d<\/strong> at the top to save your settings.<\/p>\n\n\n<div class=\"wp-block-image is-style-default\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.48.47.png\" alt=\"\" class=\"wp-image-370\" width=\"554\" height=\"220\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.48.47.png 954w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.48.47-300x119.png 300w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.48.47-768x306.png 768w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.48.47-604x241.png 604w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/figure><\/div>\n\n\n<p>Next, we need to create a Configuration profile in Intune. Click <strong>\u201cEndpoint security\u201d<\/strong> and <strong>\u201cAccount Protection\u201d<\/strong>, then <strong>\u201c+ Create Policy\u201d.<\/strong> Platform will be <strong>\u201cWindows 10 and later\u201d<\/strong>, and Profile is <strong>\u201cLocal admin password solution (Windows LAPS)\u201d<\/strong>. Click <strong>\u201cCreate\u201d<\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"489\" height=\"381\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.13.png\" alt=\"\" class=\"wp-image-372\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.13.png 489w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.13-300x234.png 300w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.13-347x270.png 347w\" sizes=\"auto, (max-width: 489px) 100vw, 489px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"481\" height=\"242\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.26.png\" alt=\"\" class=\"wp-image-380\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.26.png 481w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.37.26-300x151.png 300w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\" \/><\/figure><\/div>\n\n\n<p class=\"has-medium-font-size\"><strong>Basics:<\/strong><\/p>\n\n\n\n<p>Choose a fitting name and click \u201cNext\u201d.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Configuration settings:<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.48.20.png\" alt=\"\" class=\"wp-image-377\" width=\"495\" height=\"473\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.48.20.png 776w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.48.20-300x287.png 300w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.48.20-768x734.png 768w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-08-kl.-12.48.20-282x270.png 282w\" sizes=\"auto, (max-width: 495px) 100vw, 495px\" \/><\/figure><\/div>\n\n\n<p>Let me explain what the options means.<\/p>\n\n\n\n<p><strong>Backup directory: <\/strong>Here you will choose what directory you want to back the data up to. You can only choose one! Primarily we want Azure AD in most cases, but Active Directory can be used if needed.<\/p>\n\n\n\n<p><strong>Password Age Days:<\/strong> Quite easy. Set how old (in days) you want the password to maximum be. I like even numbers, so let\u2019s set it to 30 days.<\/p>\n\n\n\n<p><strong>Administrator Account Name: <\/strong>enable this if you have created dedicated admin-accounts with your own name and want to target the profile to these accounts instead of the default admin-account. As standard, LAPS will target the admin account with the well known SID. The default admin account on Windows machines always has the same default SID and that\u2019s why you always should disable that user and create a dedicated one. If you are using the default one, just leave this setting off. If you have created a new admin account, type in the name of that account here. This must match on all computers!<\/p>\n\n\n\n<p><strong>Password Complexity:<\/strong> Choose how complex your password should be. I prefer not having special characters but a longer password instead.<\/p>\n\n\n\n<p><strong>Password length:<\/strong> Self-explanatory? Here I like to bump it up to 20 from the default 14 characters.<\/p>\n\n\n\n<p><strong>Post Authentication Actions: <\/strong>Define what to to with the password if it\u2019s been used. The default here is \u201cReset the password and logoff the managed account\u201d. This will reset the account and log off any interactive sessions after a period of time. The grace period can be set in the next field.<\/p>\n\n\n\n<p><strong>Post Authentication Reset Delay:<\/strong> Here you define the time window before executing the specified Post Authentication Action. This is set in hours, and I like to set this a lot lower than the default 24 hours.<\/p>\n\n\n\n<p>Click <strong>\u201cNext\u201d.<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Scope tags:<\/strong><\/p>\n\n\n\n<p>This is the time to add some. If you are not using Scope tags, just click <strong>&laquo;Next&raquo;<\/strong>.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Assignments:<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.04.29-1024x371.png\" alt=\"\" class=\"wp-image-363\" width=\"420\" height=\"152\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.04.29-1024x371.png 1024w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.04.29-300x109.png 300w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.04.29-768x278.png 768w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.04.29-604x219.png 604w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.04.29.png 1082w\" sizes=\"auto, (max-width: 420px) 100vw, 420px\" \/><\/figure><\/div>\n\n\n<p>Since this is a Device-policy, you need to scope to devices and not users. If you want you can roll this out to a subset of machines in your tenant, or be brave as I am and let everyone get the policy at once by clicking <strong>\u201c+ Add all devices\u201d<\/strong>. Click <strong>\u201cNext\u201d<\/strong>.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Review + create:<\/strong><\/p>\n\n\n\n<p>If you are happy with all the settings, click <strong>\u201cCreate\u201d.<\/strong><\/p>\n\n\n\n<p>Congratulations! You have now enabled LAPS in your tenant and enabled all your computers to rotate the local admin password every 30 days. How cool! You should be seeing this rolled out pretty quickly. But what if you need to use that account\u2026?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Find the generated password<\/h2>\n\n\n\n<p>To read out a password from LAPS you need to either log in with a Global Admin, Intune Admin or Cloud Device Admin. No regular user can read out these passwords by default. Additionally we can create a custom role for this. The role needs to be this one: <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>microsoft.directory\/deviceLocalCredentials\/password\/read<\/code><\/pre>\n\n\n\n<p>Create a custom role and assign that to your help desk agents or super users so they can read out the passwords when needed.<\/p>\n\n\n\n<p>So, when you have logged in with a user that has the correct role there are several ways to find your passwords.<\/p>\n\n\n\n<p><strong>One way:<\/strong><\/p>\n\n\n\n<p>In Entra, you can go to Devices and All devices. Click <strong>\u201cLocal administrator password recovery\u201d.<\/strong> Here is every device with LAPS enabled. You can search by device name or ID and click <strong>\u201cShow local administrator password\u201d<\/strong>. A blade with Account name, SID, Local admin password and rotation info appears. Click <strong>\u201cshow\u201d<\/strong> to reveal the password.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.55.37.png\" alt=\"\" class=\"wp-image-369\" width=\"220\" height=\"288\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.55.37.png 556w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.55.37-229x300.png 229w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-09.55.37-206x270.png 206w\" sizes=\"auto, (max-width: 220px) 100vw, 220px\" \/><\/figure><\/div>\n\n\n<p><strong>Second way<\/strong><\/p>\n\n\n\n<p>This is via the intune portal. Go to <a href=\"https:\/\/intune.microsoft.com\">https:\/\/intune.microsoft.com<\/a>, click on <strong>\u201cDevices\u201d<\/strong> and on <strong>\u201cWindows\u201d.<\/strong> Search for and click on your desired device. In the Menu bar there is a button for <strong>\u201cRotate local admin password\u201d<\/strong>. This is usually hidden under the three dot menu, depending on your screen width.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.17.08.png\" alt=\"\" class=\"wp-image-361\" width=\"311\" height=\"222\" srcset=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.17.08.png 676w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.17.08-300x214.png 300w, https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-10.17.08-379x270.png 379w\" sizes=\"auto, (max-width: 311px) 100vw, 311px\" \/><\/figure><\/div>\n\n\n<p>And there is of course the way via PowerShell. See further down.<\/p>\n\n\n\n<p>If I now use this account and log on to that machine, the policy will enforce a rotation 8 hours after my first login. Even if the password is somehow snatched up and used by someone for malicious use, they will be kicked out after some time and the password will be rolled over.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who?? When??<\/h2>\n\n\n\n<p>There is also this question of who has done what, and when. I hope your logs are working because every action can be logged in your tenant. These logs can be found in the Entra-portal under Monitoring &amp; health and Audit logs. If there\u2019s a lot of logs in your tenant, you can filter for Service: Device Registration Service to see only the related logs.<\/p>\n\n\n\n<p>From there you can click on the entries you would like to investigate and see who has done what, when \u2013 and from where. If you want, you can set up alerts on these events and alert the right people when a local admin is used so the event can be monitored. But that\u2019s another blog post for another day \ud83d\ude09<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why not use PowerShell?<\/h2>\n\n\n\n<p>And lucky for us geeks that want to automate and do stuff in bulk there is a lot of ways to use LAPS via PowerShell as well. So why not use it?<\/p>\n\n\n\n<p>If you want to get a LAPS password from Azure AD via PowerShell, use this cmdlet:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" style=\"font-size:.875rem;line-height:1.25rem\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#33384d;color:#969dc4\">PowerShell<\/span><span role=\"button\" tabindex=\"0\" data-code=\"Get-LapsAADPassword -DeviceId <Array of IDs or Device names&gt;\" style=\"color:#A6ACCD;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-palenight\" style=\"background-color: #292D3E\"><code><span class=\"line\"><span style=\"color: #82AAFF\">Get-LapsAADPassword<\/span><span style=\"color: #A6ACCD\"> <\/span><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #A6ACCD\">DeviceId <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #A6ACCD\">Array of IDs or Device names<\/span><span style=\"color: #89DDFF\">&gt;<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>There can be cases when you want to reset passwords on active accounts immediately. Let\u2019s say you\u2019ve set an alert for reading passwords and no trusted personnel are using it, you can trigger this command on the device in question to reset the local admin password:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" style=\"font-size:.875rem;line-height:1.25rem\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#33384d;color:#969dc4\">PowerShell<\/span><span role=\"button\" tabindex=\"0\" data-code=\"Reset-LapsPassword\" style=\"color:#A6ACCD;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-palenight\" style=\"background-color: #292D3E\"><code><span class=\"line\"><span style=\"color: #82AAFF\">Reset-LapsPassword<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>And for investigating issues regarding LAPS, you can use this one:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" style=\"font-size:.875rem;line-height:1.25rem\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#33384d;color:#969dc4\">PowerShell<\/span><span role=\"button\" tabindex=\"0\" data-code=\"Get-LapsDiagnostics -OutpoutFolder C:\\Data\\LAPS\" style=\"color:#A6ACCD;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-palenight\" style=\"background-color: #292D3E\"><code><span class=\"line\"><span style=\"color: #82AAFF\">Get-LapsDiagnostics<\/span><span style=\"color: #A6ACCD\"> <\/span><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #A6ACCD\">OutpoutFolder C:\\<\/span><span style=\"color: #89DDFF; font-style: italic\">Data<\/span><span style=\"color: #A6ACCD\">\\LAPS<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>Read more about the PowerShell-module and see more examples here:<\/p>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-management-powershell\">https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-management-powershell<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p>I hope you find this blog useful and now want to implement LAPS in your environment. It\u2019s easy to get going and this will increase your security posture a lot by killing one of the most hated (by admins) and loved (by hackers) security concerns out there. The Windows LAPS has a lot of improvements over the legacy solution, and you can benefit from this right away.<\/p>\n\n\n\n<p>Please leave a comment to let me know how this turns out for you \ud83d\ude0a<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-overview\">https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-overview<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-faq\">https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/laps\/laps-faq<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows LAPS just recently released to Public Preview. No no, not the old one (legacy Microsoft LAPS: https:\/\/www.microsoft.com\/download\/details.aspx?id=46899). The NEW LAPS. LAPS is an acronym for Local Administrator Password Solution. On Windows-machines there is by default this almighty admin-account that gives you local administrative access to that computer. This can be used in case of emergency where other means of authentication isn\u2019t available, e.g. lost contact with domain controller. But it can also be used for malicious purposes. There are&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/\">Les mer<span class=\"screen-reader-text\"> Les mer<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":360,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-352","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Enabling and using Windows LAPS<\/title>\n<meta name=\"description\" content=\"Finally get control over your local admin passwords with Windows LAPS! Get startet in just minutes, enable this today. Let me show you how!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/\" \/>\n<meta property=\"og:locale\" content=\"nb_NO\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enabling and using Windows LAPS\" \/>\n<meta property=\"og:description\" content=\"Finally get control over your local admin passwords with Windows LAPS! Get startet in just minutes, enable this today. Let me show you how!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog.bardalen.no\" \/>\n<meta property=\"article:modified_time\" content=\"2023-05-10T08:16:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png\" \/>\n\t<meta property=\"og:image:width\" content=\"872\" \/>\n\t<meta property=\"og:image:height\" content=\"714\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Ansl. lesetid\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutter\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/\",\"url\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/\",\"name\":\"Enabling and using Windows LAPS\",\"isPartOf\":{\"@id\":\"https:\/\/blog.bardalen.no\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png\",\"datePublished\":\"2023-05-10T08:16:38+00:00\",\"dateModified\":\"2023-05-10T08:16:39+00:00\",\"description\":\"Finally get control over your local admin passwords with Windows LAPS! Get startet in just minutes, enable this today. Let me show you how!\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#breadcrumb\"},\"inLanguage\":\"nb-NO\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"nb-NO\",\"@id\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#primaryimage\",\"url\":\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png\",\"contentUrl\":\"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png\",\"width\":872,\"height\":714},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Hjem\",\"item\":\"https:\/\/blog.bardalen.no\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Enabling and using Windows LAPS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.bardalen.no\/#website\",\"url\":\"https:\/\/blog.bardalen.no\/\",\"name\":\"Blog.bardalen.no\",\"description\":\"A blog about cloudy stuff\",\"publisher\":{\"@id\":\"https:\/\/blog.bardalen.no\/#\/schema\/person\/824afefe68762a6905723a53c0f28f9a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.bardalen.no\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"nb-NO\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/blog.bardalen.no\/#\/schema\/person\/824afefe68762a6905723a53c0f28f9a\",\"name\":\"Tony Bardalen\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"nb-NO\",\"@id\":\"https:\/\/blog.bardalen.no\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/433273fdcc418ba1a5101686ae0fa85fc15baf53a2bafc63eb84bce1911caa0e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/433273fdcc418ba1a5101686ae0fa85fc15baf53a2bafc63eb84bce1911caa0e?s=96&d=mm&r=g\",\"caption\":\"Tony Bardalen\"},\"logo\":{\"@id\":\"https:\/\/blog.bardalen.no\/#\/schema\/person\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Enabling and using Windows LAPS","description":"Finally get control over your local admin passwords with Windows LAPS! Get startet in just minutes, enable this today. Let me show you how!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/","og_locale":"nb_NO","og_type":"article","og_title":"Enabling and using Windows LAPS","og_description":"Finally get control over your local admin passwords with Windows LAPS! Get startet in just minutes, enable this today. Let me show you how!","og_url":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/","og_site_name":"Blog.bardalen.no","article_modified_time":"2023-05-10T08:16:39+00:00","og_image":[{"width":872,"height":714,"url":"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Ansl. lesetid":"11 minutter"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/","url":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/","name":"Enabling and using Windows LAPS","isPartOf":{"@id":"https:\/\/blog.bardalen.no\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#primaryimage"},"image":{"@id":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png","datePublished":"2023-05-10T08:16:38+00:00","dateModified":"2023-05-10T08:16:39+00:00","description":"Finally get control over your local admin passwords with Windows LAPS! Get startet in just minutes, enable this today. Let me show you how!","breadcrumb":{"@id":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#breadcrumb"},"inLanguage":"nb-NO","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/"]}]},{"@type":"ImageObject","inLanguage":"nb-NO","@id":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#primaryimage","url":"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png","contentUrl":"https:\/\/blog.bardalen.no\/wp-content\/uploads\/2023\/05\/Skjermbilde-2023-05-05-kl.-16.10.41.png","width":872,"height":714},{"@type":"BreadcrumbList","@id":"https:\/\/blog.bardalen.no\/index.php\/enabling-and-using-windows-laps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Hjem","item":"https:\/\/blog.bardalen.no\/"},{"@type":"ListItem","position":2,"name":"Enabling and using Windows LAPS"}]},{"@type":"WebSite","@id":"https:\/\/blog.bardalen.no\/#website","url":"https:\/\/blog.bardalen.no\/","name":"Blog.bardalen.no","description":"A blog about cloudy stuff","publisher":{"@id":"https:\/\/blog.bardalen.no\/#\/schema\/person\/824afefe68762a6905723a53c0f28f9a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.bardalen.no\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"nb-NO"},{"@type":["Person","Organization"],"@id":"https:\/\/blog.bardalen.no\/#\/schema\/person\/824afefe68762a6905723a53c0f28f9a","name":"Tony Bardalen","image":{"@type":"ImageObject","inLanguage":"nb-NO","@id":"https:\/\/blog.bardalen.no\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/433273fdcc418ba1a5101686ae0fa85fc15baf53a2bafc63eb84bce1911caa0e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/433273fdcc418ba1a5101686ae0fa85fc15baf53a2bafc63eb84bce1911caa0e?s=96&d=mm&r=g","caption":"Tony Bardalen"},"logo":{"@id":"https:\/\/blog.bardalen.no\/#\/schema\/person\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/pages\/352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/comments?post=352"}],"version-history":[{"count":11,"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/pages\/352\/revisions"}],"predecessor-version":[{"id":385,"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/pages\/352\/revisions\/385"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/media\/360"}],"wp:attachment":[{"href":"https:\/\/blog.bardalen.no\/index.php\/wp-json\/wp\/v2\/media?parent=352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}