Looks after a device's local administrator password and keeps a copy in Active Directory or Microsoft Entra ID. It is set up through Intune account protection policies.
Also called Windows Local Administrator Password Solution.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Windows LAPS in context, with comparison tables and the common traps.
Terms in this definition
- LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Account protection
Covers Windows LAPS, local user group membership, Credential Guard and Windows Hello for Business in a single Intune endpoint security policy type for Windows. Since July 2024 it has replaced the Identity protection template.
Related terms
- Legacy Microsoft LAPS emulation mode
A compatibility setting in which Windows LAPS behaves like its predecessor, honouring old-style policy and writing passwords into the earlier directory attributes.