Windows LAPS: Rethinking Local Administrator Management
A practical series exploring how to design, manage and operate Windows LAPS across Windows 11, Intune, Group Policy and Windows Server.
Windows LAPS solves an important problem, but local administrator security is about more than rotating a password.
In this series, I'll explore how Windows LAPS fits into a modern endpoint and server security architecture, from Windows 11 and Automatic Account Management through to Intune vs Group Policy, Windows Server, credential recovery and day-to-day operations.
Rather than simply walking through the settings, I'll focus on the decisions behind them:
- What local administrator accounts should actually exist?
- Should LAPS manage the built-in Administrator or create and manage its own account?
- When should Intune own the configuration, and when does Group Policy still make sense?
- How should the design differ between Windows 11 and Windows Server?
- Who can retrieve a LAPS credential, and what happens after it's been used?
- How do we identify and remove the unmanaged local privilege that LAPS doesn't automatically solve?
The goal is to move beyond "we've enabled LAPS" and look at what a properly designed, managed and operational local administrator model actually looks like.
Articles in this series
Get notified about new posts
Drop your email in and I'll let you know when there's something new — from the whole blog, or just Windows LAPS: Rethinking Local Administrator Management.