
Other related features like administrative units, custom roles, Conditional Access, and Intune have other licensing requirements. LAPS is available to all customers with Azure AD Free or higher licenses. Azure AD registered devices aren't supported. LAPS is supported on Azure AD joined or hybrid Azure AD joined devices only.
#Save passwords update
This feature is now available on the following Windows OS platforms with the specified update or later installed: This feature is now available in the following Azure clouds: Requirements Supported Azure regions and Windows distributions Microsoft Intune support for Windows LAPS.Intune policy for LAPS uses these settings to configure the LAPS CSP on devices.
#Save passwords full
Windows LAPS CSP – View the full details for LAPS settings and options.What is Windows LAPS? – Introduction to Windows LAPS and the Windows LAPS documentation set.To learn about Windows LAPS in more detail, start with the following articles in the Windows documentation: Local Administrator Password Solution isn't supported on non-Windows platforms. Windows LAPS with Azure AD is not supported for Windows devices that are Azure AD registered. Conditional Access policies for local administrator password recovery - Configure Conditional Access policies on directory roles that have the authorization of password recovery.Auditing local administrator password update and recovery - Use audit logs API/Portal experiences to monitor password update and recovery events.Authorization of local administrator password recovery - Use role based access control (RBAC) policies with custom roles and administrative units.Enumerating all Windows LAPS enabled devices - Use API/Portal experiences to enumerate all Windows devices in Azure AD enabled with Windows LAPS.Recovering local administrator password - Use API/Portal experiences for local administrator password recovery.
#Save passwords manual

Many customers have been using our standalone, on-premises Local Administrator Password Solution (LAPS) product for local administrator password management of their domain joined Windows machines. See the Supplemental Terms of Use for Microsoft Azure Previews for legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.Įvery Windows device comes with a built-in local administrator account that you must secure and protect to mitigate any Pass-the-Hash (PtH) and lateral traversal attacks. Azure AD support for Windows Local Administrator Password Solution is currently in preview.
