Skip to content

Deploy Windows LAPS with Active Directory Backup

Windows Local Administrator Password Solution (Windows LAPS) manages and backs up local administrator passwords for supported Windows devices. This walkthrough configures backup to Windows Server Active Directory (AD DS), scopes policy to a workstation organizational unit (OU), and verifies that a client successfully backs up its password.

Run the directory preparation from an appropriately delegated administrative system. Pilot the policy with a small test OU before broad deployment. Passwords are sensitive credentials: grant read and decryption access only to approved support groups and retrieve a password only when needed.


Step 1: Check the Domain and Target OU

01

Confirm the AD Environment and Pilot Scope

Prerequisites

Use a management system with the Active Directory and Windows LAPS PowerShell modules. Choose the workstation OU and an approved password reader group before changing the schema or linking policy. Active Directory password encryption requires a domain functional level of Windows Server 2016 or later.

Terminal window
Import-Module ActiveDirectory
Import-Module LAPS
Get-ADForest | Select-Object Name, ForestMode
Get-ADDomain | Select-Object DNSRoot, DomainMode
Get-Module -ListAvailable LAPS
❯ View Expected Console Output
Name : contoso.com
ForestMode : Windows2016Forest
DNSRoot : contoso.com
DomainMode : Windows2016Domain

Step 2: Extend the Schema and Delegate Access

02

Prepare AD and Grant Scoped Permissions

Directory Setup

Extend the AD schema once per forest with the Windows LAPS attributes. Then grant computer accounts in the pilot OU permission to update their own password attributes. Delegate password reading to a narrowly scoped support group. The schema update requires Schema Admin rights; use an approved change window and directory change process.

Terminal window
$TargetOU = "OU=Workstations,DC=contoso,DC=com"
$ReaderGroup = "CONTOSO\LAPS-Password-Readers"
Update-LapsADSchema -Verbose
Set-LapsADComputerSelfPermission -Identity $TargetOU
Set-LapsADReadPasswordPermission -Identity $TargetOU `
-AllowedPrincipals $ReaderGroup
❯ View Expected Console Output
Schema update completed.
Self permission granted for the selected OU.
Read password permission granted to CONTOSO\LAPS-Password-Readers.

Step 3: Configure a Scoped LAPS Policy

03

Set the AD Backup and Password Rules

Group Policy

In Group Policy Management, create a Windows LAPS policy and link it to the pilot workstation OU. Under Computer Configuration > Policies > Administrative Templates > System > LAPS, configure the AD backup directory, password settings, and encryption. Set the authorized decryptor to the approved reader group so the encryption principal matches the people who need to recover passwords.

If you use a Central Store for policy definitions, ensure its LAPS ADMX/ADML files are current enough to expose the Windows LAPS settings. Keep the policy link and security filtering limited to the pilot computers.

Backup directory: Active Directory
Password age: 30 days
Password length: 20 characters
Password complexity: 4 (uppercase, lowercase, numbers, special characters)
Password encryption: Enabled
Authorized decryptor: CONTOSO\LAPS-Password-Readers
Policy link: OU=Workstations,DC=contoso,DC=com
❯ View Expected Console Output
Windows LAPS policy linked to the pilot OU and scoped to test computers.
Group Policy Management Editor showing Windows LAPS policy settings configured for Active Directory backup

Figure 1: Windows LAPS settings in the Group Policy Management Editor.


Step 4: Apply Policy and Check the Client Event Log

04

Trigger Processing on a Pilot Workstation

Verification

On a supported, domain-joined test workstation in the target OU, refresh computer policy and ask Windows LAPS to process it immediately. Review the Operational log for a successful AD backup event. Event ID 10018 indicates that the password was successfully backed up to Active Directory.

Terminal window
gpupdate /target:computer /force
Invoke-LapsPolicyProcessing
Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 10 |
Select-Object TimeCreated, Id, LevelDisplayName, Message
❯ View Expected Console Output
TimeCreated Id LevelDisplayName
----------- -- ----------------
... 10018 Information
Event Viewer showing Windows LAPS Operational event 10018 for successful Active Directory password backup

Figure 2: Windows LAPS Operational log with event 10018 selected.


Step 5: Retrieve a Password Only When Authorized

05

Read the Managed Password Securely

Operations

Use the LAPS PowerShell module from an approved administrative session. The command returns the password as a SecureString by default. Do not add -AsPlainText unless an approved recovery workflow requires clear text, and avoid recording the secret in transcripts, tickets, or shell history.

Terminal window
Get-LapsADPassword -Identity "WS-01"
❯ View Expected Console Output
ComputerName : WS-01
Password : System.Security.SecureString
ExpirationTimestamp : ...
Source : ActiveDirectory
Windows PowerShell showing Get-LapsADPassword returning a SecureString for WS-01

Figure 3: Retrieve the managed password as a SecureString.

Comments