Bankesy Posted June 5, 2024 Posted June 5, 2024 Good afternoon, Hoping somebody who has got LAPS working via Intune can tell me what I'm missing, I've basically got it switched on and can see the option per device to refresh the password but nothing happens. Thanks
Steve21 Posted June 5, 2024 Posted June 5, 2024 Can you narrow down what you have done Bit easier than guessing! Even a screenshot of your config to compare to ours etc Steve
Bankesy Posted June 5, 2024 Author Posted June 5, 2024 @Steve21 Sure, in Microsoft Entra admin centre>Identity>Devices>All devices>Device settings I switched on Enable Microsoft Entra Local Administrator Password Solution (LAPS)
Steve21 Posted June 5, 2024 Posted June 5, 2024 (edited) If that's the only bit you've done you haven't actually deployed a policy yet (That only enables the option) Go to InTune Admin portal EndPoint Security -> Account Protection -> Create a policy (Win10 later + LAPS) and you need to configure it up there with settings and deploy it to a group LAPS Backup Directory - Backup the password to Azure AD only Password Age Days - 30 Password Complexity - Large letters + small letters + numbers + special characters Password Length - 14 Post Authentication Actions - Reset the password and reboot: upon expiry of the grace period, the managed account password will be reset and the managed device will be immediately rebooted. Post Authentication Reset Delay - 24 Example of what we use Additionally, make sure you've actually enabled local admin account if you're using AutoPilot etc, else you need to add the "custom" admin name in the policy for it to affect that if you use LocalAdmin or something else Steve Edited June 5, 2024 by Steve21 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now