Jump to content

Recommended Posts

Posted

Good afternoon,

 

Hoping somebody who has got LAPS working via Intune can tell me what I'm missing, I've basically got it switched on and can see the option per device to refresh the password but nothing happens.

 

Thanks

Posted

@Steve21

 

Sure, in Microsoft Entra admin centre>Identity>Devices>All devices>Device settings

 

I switched on Enable Microsoft Entra Local Administrator Password Solution (LAPS)

Posted (edited)

If that's the only bit you've done you haven't actually deployed a policy yet (That only enables the option)

 

Go to InTune Admin portal

 

EndPoint Security -> Account Protection -> Create a policy (Win10 later + LAPS) and you need to configure it up there with settings and deploy it to a group

 

LAPS
Backup Directory - Backup the password to Azure AD only
Password Age Days - 30
Password Complexity - Large letters + small letters + numbers + special characters
Password Length - 14

Post Authentication Actions - Reset the password and reboot: upon expiry of the grace period, the managed account password will be reset and the managed device will be immediately rebooted.
Post Authentication Reset Delay - 24

 

Example of what we use

 

Additionally, make sure you've actually enabled local admin account if you're using AutoPilot etc, else you need to add the "custom" admin name in the policy for it to affect that if you use LocalAdmin or something else

 

Steve

Edited by Steve21
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...