Deploy Windows LAPS with Active Directory Backup
Windows Local Administrator Password Solution (Windows LAPS) manages and backs up local administrator passwords for supported Windows devices. This walkthrough configures backup to Windows Server Active Directory (AD DS), scopes policy to a workstation organizational unit (OU), and verifies that a client successfully backs up its password.
Run the directory preparation from an appropriately delegated administrative system. Pilot the policy with a small test OU before broad deployment. Passwords are sensitive credentials: grant read and decryption access only to approved support groups and retrieve a password only when needed.
Step 1: Check the Domain and Target OU
Confirm the AD Environment and Pilot Scope
PrerequisitesUse a management system with the Active Directory and Windows LAPS PowerShell modules. Choose the workstation OU and an approved password reader group before changing the schema or linking policy. Active Directory password encryption requires a domain functional level of Windows Server 2016 or later.
Import-Module ActiveDirectoryImport-Module LAPS
Get-ADForest | Select-Object Name, ForestModeGet-ADDomain | Select-Object DNSRoot, DomainModeGet-Module -ListAvailable LAPS❯ View Expected Console Output
Name : contoso.comForestMode : Windows2016ForestDNSRoot : contoso.comDomainMode : Windows2016DomainStep 2: Extend the Schema and Delegate Access
Prepare AD and Grant Scoped Permissions
Directory SetupExtend the AD schema once per forest with the Windows LAPS attributes. Then grant computer accounts in the pilot OU permission to update their own password attributes. Delegate password reading to a narrowly scoped support group. The schema update requires Schema Admin rights; use an approved change window and directory change process.
$TargetOU = "OU=Workstations,DC=contoso,DC=com"$ReaderGroup = "CONTOSO\LAPS-Password-Readers"
Update-LapsADSchema -VerboseSet-LapsADComputerSelfPermission -Identity $TargetOUSet-LapsADReadPasswordPermission -Identity $TargetOU ` -AllowedPrincipals $ReaderGroup❯ View Expected Console Output
Schema update completed.Self permission granted for the selected OU.Read password permission granted to CONTOSO\LAPS-Password-Readers.Step 3: Configure a Scoped LAPS Policy
Set the AD Backup and Password Rules
Group PolicyIn Group Policy Management, create a Windows LAPS policy and link it to the pilot workstation OU. Under Computer Configuration > Policies > Administrative Templates > System > LAPS, configure the AD backup directory, password settings, and encryption. Set the authorized decryptor to the approved reader group so the encryption principal matches the people who need to recover passwords.
If you use a Central Store for policy definitions, ensure its LAPS ADMX/ADML files are current enough to expose the Windows LAPS settings. Keep the policy link and security filtering limited to the pilot computers.
Backup directory: Active DirectoryPassword age: 30 daysPassword length: 20 charactersPassword complexity: 4 (uppercase, lowercase, numbers, special characters)Password encryption: EnabledAuthorized decryptor: CONTOSO\LAPS-Password-ReadersPolicy link: OU=Workstations,DC=contoso,DC=com❯ View Expected Console Output
Windows LAPS policy linked to the pilot OU and scoped to test computers.
Figure 1: Windows LAPS settings in the Group Policy Management Editor.
Step 4: Apply Policy and Check the Client Event Log
Trigger Processing on a Pilot Workstation
VerificationOn a supported, domain-joined test workstation in the target OU, refresh computer policy and ask Windows LAPS to process it immediately. Review the Operational log for a successful AD backup event. Event ID 10018 indicates that the password was successfully backed up to Active Directory.
gpupdate /target:computer /forceInvoke-LapsPolicyProcessing
Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 10 | Select-Object TimeCreated, Id, LevelDisplayName, Message❯ View Expected Console Output
TimeCreated Id LevelDisplayName----------- -- ----------------... 10018 Information
Figure 2: Windows LAPS Operational log with event 10018 selected.
Step 5: Retrieve a Password Only When Authorized
Read the Managed Password Securely
OperationsUse the LAPS PowerShell module from an approved administrative session. The command returns the password as a SecureString by default. Do not add -AsPlainText unless an approved recovery workflow requires clear text, and avoid recording the secret in transcripts, tickets, or shell history.
Get-LapsADPassword -Identity "WS-01"❯ View Expected Console Output
ComputerName : WS-01Password : System.Security.SecureStringExpirationTimestamp : ...Source : ActiveDirectory
Figure 3: Retrieve the managed password as a SecureString.