Skip to content
Active

Windows LAPS: Rethinking Local Administrator Management

A practical series exploring how to design, manage and operate Windows LAPS across Windows 11, Intune, Group Policy and Windows Server.

1 of 1 published · ~10 min total reading

Windows LAPS solves an important problem, but local administrator security is about more than rotating a password.

In this series, I'll explore how Windows LAPS fits into a modern endpoint and server security architecture, from Windows 11 and Automatic Account Management through to Intune vs Group Policy, Windows Server, credential recovery and day-to-day operations.

Rather than simply walking through the settings, I'll focus on the decisions behind them:

  • What local administrator accounts should actually exist?
  • Should LAPS manage the built-in Administrator or create and manage its own account?
  • When should Intune own the configuration, and when does Group Policy still make sense?
  • How should the design differ between Windows 11 and Windows Server?
  • Who can retrieve a LAPS credential, and what happens after it's been used?
  • How do we identify and remove the unmanaged local privilege that LAPS doesn't automatically solve?

The goal is to move beyond "we've enabled LAPS" and look at what a properly designed, managed and operational local administrator model actually looks like.

Articles in this series

  1. Introduction Windows LAPS: More Than Password Rotation