FREE STUDY NOTES · AZ-802

Windows LAPS: backing up local administrator passwords to AD DS or Microsoft Entra ID

How Windows LAPS rotates and stores local administrator passwords, its policy settings, encryption and the cmdlets to retrieve them.

From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)

Windows Local Administrator Password Solution (Windows LAPS) rotates the password of a local administrator account on every device and backs it up to a directory, so no two servers share a local administrator password. On domain controllers it can manage the DSRM password instead.

Platforms and backup targets

Windows LAPS is built into Windows Server 2025, and into Windows Server 2022 and 2019 with the 11 April 2023 update or later; nothing needs to be installed. It’s free; backing up to Microsoft Entra ID needs Microsoft Entra ID Free or higher.

Device join state Can back up to
Active Directory joined only Windows Server Active Directory only
Microsoft Entra joined only Microsoft Entra ID only
Microsoft Entra hybrid joined Either AD or Entra ID, but not both
Microsoft Entra registered (workplace joined) Not supported

The BackupDirectory setting selects the target: 0 = Disabled (the default, so nothing happens until policy is set), 1 = Microsoft Entra ID, 2 = Active Directory.

Common trap: Configuring a hybrid-joined server to back up its LAPS password to both AD and Microsoft Entra ID for redundancy - Windows LAPS can back up to only one directory at a time.

Preparing Active Directory

  1. Extend the schema with Update-LapsADSchema (Windows LAPS uses its own attributes, separate from legacy LAPS).
  2. Grant computers permission to update their own password with Set-LapsADComputerSelfPermission -Identity <OU>.
  3. Grant read and reset rights to administrators as needed with Set-LapsADReadPasswordPermission and Set-LapsADResetPasswordPermission; Find-LapsADExtendedRights shows who has rights.
  4. Configure policy through Group Policy (Computer Configuration > Policies > Administrative Templates > System > LAPS, from LAPS.admx) or the LAPS CSP for Entra-joined devices. Copy LAPS.admx to the central store manually; Windows Update doesn’t do it.

Key policy settings and defaults

Setting Default Notes
BackupDirectory Disabled 1 = Entra ID, 2 = AD
AdministratorAccountName Built-in Administrator (by RID) Set only for a custom account; LAPS doesn’t create it (unless automatic account management is used)
PasswordAgeDays 30 1 to 365 (minimum 7 with Entra ID); changes don’t trigger rotation
PasswordLength 14 8 to 64
PasswordComplexity 4 (upper, lower, numbers, specials) 5-8 (improved readability, passphrases) need Windows Server 2025
ADPasswordEncryptionEnabled True Requires domain functional level 2016 or later
ADPasswordEncryptionPrincipal Domain Admins Who can decrypt the AD-stored password
ADEncryptedPasswordHistorySize 0 Up to 12 previous passwords (encryption required)
ADBackupDSRMPassword False DCs only; requires encryption
PostAuthenticationResetDelay / Actions 24 hours / 3 (reset password and sign out) Rotates after the password is used
AutomaticAccountManagementEnabled False Windows Server 2025: LAPS creates and manages the account (default name WLapsAdmin)

Windows LAPS processes policy every hour in a background task that isn’t tied to the Group Policy refresh cycle; run Invoke-LapsPolicyProcessing to process immediately and Reset-LapsPassword to rotate now. Successful AD updates log event 10018, Entra ID updates event 10029.

Update-LapsADSchema
Set-LapsADComputerSelfPermission -Identity "OU=Servers,DC=corp,DC=example"
Get-LapsADPassword -Identity SRV01 -AsPlainText

Passwords stored in AD can also be viewed in the computer’s properties dialog box in Active Directory Users and Computers. Encrypted passwords can be read only by the configured principal.

Legacy Microsoft LAPS

The legacy Microsoft LAPS MSI is deprecated: newer OS versions block its installation and it receives no code changes. Legacy Microsoft LAPS emulation mode lets Windows LAPS honour existing legacy LAPS Group Policy settings during migration, but only if the legacy client-side extension isn’t installed, and native Windows LAPS settings take precedence when both are present. Emulation mode stores passwords in clear text and can’t use encryption or password history, so treat it as temporary.

Cmdlet task Windows LAPS Legacy LAPS
Read password Get-LapsADPassword Get-AdmPwdPassword
Extend schema Update-LapsADSchema Update-AdmPwdADSchema
Computer self-permission Set-LapsADComputerSelfPermission Set-AdmPwdComputerSelfPermission
Force expiry Set-LapsADPasswordExpirationTime Reset-AdmPwdPassword
Rotate immediately on device Reset-LapsPassword Not available

Get the whole book

This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · AZ-802 terms in the glossary · All AZ-802 study notes

More AZ-802 study notes