How Windows LAPS rotates and stores local administrator passwords, its policy settings, encryption and the cmdlets to retrieve them.
From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)
Windows Local Administrator Password Solution (Windows LAPS) rotates the password of a local administrator account on every device and backs it up to a directory, so no two servers share a local administrator password. On domain controllers it can manage the DSRM password instead.
Windows LAPS is built into Windows Server 2025, and into Windows Server 2022 and 2019 with the 11 April 2023 update or later; nothing needs to be installed. It’s free; backing up to Microsoft Entra ID needs Microsoft Entra ID Free or higher.
| Device join state | Can back up to |
|---|---|
| Active Directory joined only | Windows Server Active Directory only |
| Microsoft Entra joined only | Microsoft Entra ID only |
| Microsoft Entra hybrid joined | Either AD or Entra ID, but not both |
| Microsoft Entra registered (workplace joined) | Not supported |
The BackupDirectory setting selects the target: 0 = Disabled (the default, so nothing happens until policy is set), 1 = Microsoft Entra ID, 2 = Active Directory.
Common trap: Configuring a hybrid-joined server to back up its LAPS password to both AD and Microsoft Entra ID for redundancy - Windows LAPS can back up to only one directory at a time.
Update-LapsADSchema (Windows LAPS uses its own attributes, separate from legacy LAPS).Set-LapsADComputerSelfPermission -Identity <OU>.Set-LapsADReadPasswordPermission and Set-LapsADResetPasswordPermission; Find-LapsADExtendedRights shows who has rights.LAPS.admx) or the LAPS CSP for Entra-joined devices. Copy LAPS.admx to the central store manually; Windows Update doesn’t do it.| Setting | Default | Notes |
|---|---|---|
| BackupDirectory | Disabled | 1 = Entra ID, 2 = AD |
| AdministratorAccountName | Built-in Administrator (by RID) | Set only for a custom account; LAPS doesn’t create it (unless automatic account management is used) |
| PasswordAgeDays | 30 | 1 to 365 (minimum 7 with Entra ID); changes don’t trigger rotation |
| PasswordLength | 14 | 8 to 64 |
| PasswordComplexity | 4 (upper, lower, numbers, specials) | 5-8 (improved readability, passphrases) need Windows Server 2025 |
| ADPasswordEncryptionEnabled | True | Requires domain functional level 2016 or later |
| ADPasswordEncryptionPrincipal | Domain Admins | Who can decrypt the AD-stored password |
| ADEncryptedPasswordHistorySize | 0 | Up to 12 previous passwords (encryption required) |
| ADBackupDSRMPassword | False | DCs only; requires encryption |
| PostAuthenticationResetDelay / Actions | 24 hours / 3 (reset password and sign out) | Rotates after the password is used |
| AutomaticAccountManagementEnabled | False | Windows Server 2025: LAPS creates and manages the account (default name WLapsAdmin) |
Windows LAPS processes policy every hour in a background task that isn’t tied to the Group Policy refresh cycle; run Invoke-LapsPolicyProcessing to process immediately and Reset-LapsPassword to rotate now. Successful AD updates log event 10018, Entra ID updates event 10029.
Update-LapsADSchema
Set-LapsADComputerSelfPermission -Identity "OU=Servers,DC=corp,DC=example"
Get-LapsADPassword -Identity SRV01 -AsPlainTextPasswords stored in AD can also be viewed in the computer’s properties dialog box in Active Directory Users and Computers. Encrypted passwords can be read only by the configured principal.
The legacy Microsoft LAPS MSI is deprecated: newer OS versions block its installation and it receives no code changes. Legacy Microsoft LAPS emulation mode lets Windows LAPS honour existing legacy LAPS Group Policy settings during migration, but only if the legacy client-side extension isn’t installed, and native Windows LAPS settings take precedence when both are present. Emulation mode stores passwords in clear text and can’t use encryption or password history, so treat it as temporary.
| Cmdlet task | Windows LAPS | Legacy LAPS |
|---|---|---|
| Read password | Get-LapsADPassword |
Get-AdmPwdPassword |
| Extend schema | Update-LapsADSchema |
Update-AdmPwdADSchema |
| Computer self-permission | Set-LapsADComputerSelfPermission |
Set-AdmPwdComputerSelfPermission |
| Force expiry | Set-LapsADPasswordExpirationTime |
Reset-AdmPwdPassword |
| Rotate immediately on device | Reset-LapsPassword |
Not available |
This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AZ-802 terms in the glossary · All AZ-802 study notes
Which operations master roles exist per forest and per domain, what each does and the placement guidance for each.
When to deploy an RODC, how staged installation works and how the allowed and denied groups decide which passwords are cached.
Which managed service account type fits a service, its requirements such as the KDS root key, and how Windows Server 2025 delegated MSAs migrate old accounts.
The LSDOU order, which GPO wins a conflict, and how Block Inheritance, Enforced and link order change the result.
How the two DHCP failover modes split or reserve addresses, what MCLT does and how relay agents fit in.
What SMB over QUIC needs on the server, the certificate rules, which editions support it and how client access control works.
The Storage Replica topologies, when to use synchronous or asynchronous mode, log volume requirements and the Standard edition limits.