Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.
From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)
Windows LAPS (Windows Local Administrator Password Solution) is built into Windows. It manages the password of one local administrator account per device, rotates it on a schedule and backs it up to Microsoft Entra ID or on-premises Active Directory. Intune configures it through the Windows LAPS CSP.
| Device | Back up to Microsoft Entra ID | Back up to Active Directory |
|---|---|---|
| Microsoft Entra joined | Yes, after enabling LAPS in Entra device settings | No (policy applies but backup fails) |
| Microsoft Entra hybrid joined | Yes, no Entra tenant switch needed | Yes |
| Microsoft Entra registered (workplace joined) | Not supported | Not supported |
A device backs up to one directory, never both. For Microsoft Entra joined devices, a Cloud Device Administrator turns on Enable Microsoft Entra Local Administrator Password Solution (LAPS) under Entra ID > Devices > Overview > Device settings.
Go to Endpoint security > Account protection > Create Policy, platform Windows, profile Local admin password solution (Windows LAPS). Creating or viewing the policy needs the Intune Security baselines permissions, which the built-in Endpoint Security Manager role includes. Microsoft recommends one LAPS policy per device, assigned to device groups; user-group assignment makes the configuration change as different people sign in. Intune’s CSP-based policy takes precedence over LAPS Group Policy and legacy Microsoft LAPS.
| Setting | Default | Range or note |
|---|---|---|
| BackupDirectory | Disabled (0) | 1 = Microsoft Entra ID, 2 = Active Directory |
| AdministratorAccountName | Built-in Administrator (by RID) | LAPS doesn’t create a custom account; a missing name means nothing is managed |
| PasswordAgeDays | 30 | 1 to 365; minimum 7 when backing up to Entra ID |
| PasswordLength | 14 | 8 to 64 |
| PasswordComplexity | 4 (upper, lower, numbers, specials) | 5 to 8 (readability and passphrases) need Windows 11 24H2 |
| PassphraseLength | 6 words | 3 to 10; Windows 11 24H2 |
| PostAuthenticationResetDelay | 24 hours | 0 to 24; 0 disables post-authentication actions |
| PostAuthenticationActions | 3 (reset password and sign out) | 1 reset; 5 reset and reboot; 11 also ends processes (24H2) |
| Automatic account management | Off | Windows 11 24H2: manage built-in or a new custom account (default name WLapsAdmin), enable or disable it, randomise the name |
Changing PasswordAgeDays doesn’t alter the current password’s expiry or force a rotation. A device that receives two conflicting LAPS policies at once gets neither, and both show as conflicts.
| Task | Permission |
|---|---|
| Read password and metadata | microsoft.directory/deviceLocalCredentials/password/read: Cloud Device Administrator, Intune Administrator, or a custom Entra role |
| Read metadata only | deviceLocalCredentials/standard/read: also Helpdesk Administrator, Security Administrator, Security Reader |
| Rotate on demand from Intune | Intune custom role with Managed devices Read, Organization Read and Remote tasks Rotate Local Admin Password |
The password is viewed on the device’s Local admin password pane in Intune (or in the Entra admin center), and each retrieval writes an audit event. Passwords backed up to Active Directory can’t be viewed in Intune. The Rotate local admin password device action works one device at a time (no bulk action), resets the PasswordAgeDays clock, and fails on Microsoft Entra joined devices that are offline. Rotation and backup stop if the device is disabled in Entra, and deleting the device object in Entra loses the stored password.
Common trap: Expecting the Intune Administrator role to rotate LAPS passwords from the admin center - the Rotate Local Admin Password remote task isn’t in any built-in Intune role or the Intune Administrator Entra role; it needs a custom Intune role.
Common trap: Assigning a LAPS policy that backs up to Microsoft Entra ID without enabling LAPS in Entra device settings - for Microsoft Entra joined devices the tenant setting must be Yes or the password isn’t escrowed.
This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · MD-102 terms in the glossary · All MD-102 study notes
How Microsoft Entra registered, Entra joined and hybrid joined devices differ in ownership, sign-in, management and the scenarios each one suits.
The tenant-wide compliance settings and per-platform policies behind Intune compliance, and how a device's overall status is worked out.
The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.
How user-driven, pre-provisioned and self-deploying Autopilot modes differ in join type, user interaction and TPM requirements.
What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.
Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.
How Intune update rings set quality and feature update deferrals, deadlines, grace periods and restart behaviour for groups of Windows devices.
How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.