FREE STUDY NOTES · MD-102

Windows LAPS with Intune and Microsoft Entra ID

Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.

From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)

Windows LAPS (Windows Local Administrator Password Solution) is built into Windows. It manages the password of one local administrator account per device, rotates it on a schedule and backs it up to Microsoft Entra ID or on-premises Active Directory. Intune configures it through the Windows LAPS CSP.

Prerequisites

Device Back up to Microsoft Entra ID Back up to Active Directory
Microsoft Entra joined Yes, after enabling LAPS in Entra device settings No (policy applies but backup fails)
Microsoft Entra hybrid joined Yes, no Entra tenant switch needed Yes
Microsoft Entra registered (workplace joined) Not supported Not supported

A device backs up to one directory, never both. For Microsoft Entra joined devices, a Cloud Device Administrator turns on Enable Microsoft Entra Local Administrator Password Solution (LAPS) under Entra ID > Devices > Overview > Device settings.

Creating the policy

Go to Endpoint security > Account protection > Create Policy, platform Windows, profile Local admin password solution (Windows LAPS). Creating or viewing the policy needs the Intune Security baselines permissions, which the built-in Endpoint Security Manager role includes. Microsoft recommends one LAPS policy per device, assigned to device groups; user-group assignment makes the configuration change as different people sign in. Intune’s CSP-based policy takes precedence over LAPS Group Policy and legacy Microsoft LAPS.

Setting Default Range or note
BackupDirectory Disabled (0) 1 = Microsoft Entra ID, 2 = Active Directory
AdministratorAccountName Built-in Administrator (by RID) LAPS doesn’t create a custom account; a missing name means nothing is managed
PasswordAgeDays 30 1 to 365; minimum 7 when backing up to Entra ID
PasswordLength 14 8 to 64
PasswordComplexity 4 (upper, lower, numbers, specials) 5 to 8 (readability and passphrases) need Windows 11 24H2
PassphraseLength 6 words 3 to 10; Windows 11 24H2
PostAuthenticationResetDelay 24 hours 0 to 24; 0 disables post-authentication actions
PostAuthenticationActions 3 (reset password and sign out) 1 reset; 5 reset and reboot; 11 also ends processes (24H2)
Automatic account management Off Windows 11 24H2: manage built-in or a new custom account (default name WLapsAdmin), enable or disable it, randomise the name

Changing PasswordAgeDays doesn’t alter the current password’s expiry or force a rotation. A device that receives two conflicting LAPS policies at once gets neither, and both show as conflicts.

Viewing and rotating passwords

Task Permission
Read password and metadata microsoft.directory/deviceLocalCredentials/password/read: Cloud Device Administrator, Intune Administrator, or a custom Entra role
Read metadata only deviceLocalCredentials/standard/read: also Helpdesk Administrator, Security Administrator, Security Reader
Rotate on demand from Intune Intune custom role with Managed devices Read, Organization Read and Remote tasks Rotate Local Admin Password

The password is viewed on the device’s Local admin password pane in Intune (or in the Entra admin center), and each retrieval writes an audit event. Passwords backed up to Active Directory can’t be viewed in Intune. The Rotate local admin password device action works one device at a time (no bulk action), resets the PasswordAgeDays clock, and fails on Microsoft Entra joined devices that are offline. Rotation and backup stop if the device is disabled in Entra, and deleting the device object in Entra loses the stored password.

Common trap: Expecting the Intune Administrator role to rotate LAPS passwords from the admin center - the Rotate Local Admin Password remote task isn’t in any built-in Intune role or the Intune Administrator Entra role; it needs a custom Intune role.

Common trap: Assigning a LAPS policy that backs up to Microsoft Entra ID without enabling LAPS in Entra device settings - for Microsoft Entra joined devices the tenant setting must be Yes or the password isn’t escrowed.

Get the whole book

This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · MD-102 terms in the glossary · All MD-102 study notes

More MD-102 study notes