Icon

Intune LAPS

Unique, rotating local admin passwords on every Windows device. Backed up to Entra ID. No more shared secret that opens every laptop.

One Local Admin Password on Every Device Is Always on Every Device


On most mid-market Windows devices, the local administrator password is the same. It was set during imaging five years ago. It is written in a password manager. It is shared with the helpdesk. One phished credential, one stolen laptop, and an attacker has the key to every other device — classic lateral movement.


This is not a failure of your IT team. Legacy Microsoft LAPS needed on-prem AD, GPO, a schema extension, an MSI agent, and careful maintenance. Windows LAPS changed that: it ships in Windows 11 — out of the box from 23H2, and from the April 2023 update on 21H2 and 22H2 — is managed via Intune, and backs up to Entra ID. The license is already yours. What is missing: the policy design, the migration from legacy Microsoft LAPS or static passwords, and the operational runbook.


Traditional consulting for LAPS? Five figures. The consultant configures, leaves a document, leaves. Your helpdesk is back to sharing a password next time somebody new joins.

ACTIVITIES IN DETAIL

DELIVERABLES

  • Prerequisites: Intune licensing, Windows builds, April 2023 update, enrollment and sync state

  • Current State: Static shared passwords, legacy Microsoft LAPS, and unmanaged devices

  • Target Design: Backup directory, managed account, complexity, rotation interval, and reset delay

  • Retrieval Access: Who retrieves a password and which role they hold, built-in or least-privilege

  • Tenant and Policy: Windows LAPS enabled, Intune policy created, conflicting policies ruled out

  • Pilot: 3-5 devices checked for backup, retrieval, login, and post-authentication rotation

  • Rollout and Retirement: All target groups monitored, legacy GPO unlinked and MSI uninstalled

3 steps. From start to finished project

How a typical Microsoft project runs with DAMALO

STEP 1

Choose a blueprint and analyze your environment

Select a proven blueprint. AI agents pull your licenses, current config, and compliance needs into the plan. No generic advice.

STEP 2

Receive your plan and start implementation

Review the plan. AI agents draft architecture, sequence tasks, and map dependencies to Microsoft best practices. Tailored to your tenant.

STEP 3

Guided implementation through to completion

Execute step by step. AI agents provide PowerShell scripts, admin center deep-links, and walkthroughs. Every change auto-documented.

The result: A completed Microsoft project in 1-2 weeks. Documented. Audit-ready. Understood by your team. Adjustable at any time. No change requests. No follow-up engagements.

3 steps. From start to finished project

How a typical Microsoft project runs with DAMALO

STEP 1

Choose a blueprint and analyze your environment

Select a proven blueprint. AI agents pull your licenses, current config, and compliance needs into the plan. No generic advice.

STEP 2

Receive your plan and start implementation

Review the plan. AI agents draft architecture, sequence tasks, and map dependencies to Microsoft best practices. Tailored to your tenant.

STEP 3

Guided implementation through to completion

Execute step by step. AI agents provide PowerShell scripts, admin center deep-links, and walkthroughs. Every change auto-documented.

The result: A completed Microsoft project in 1-2 weeks. Documented. Audit-ready. Understood by your team. Adjustable at any time. No change requests. No follow-up engagements.

Next steps after Intune LAPS

A cleanly configured tenant is the foundation. These blueprints build directly on it

Icon
Intune Device Enrollment

Microsoft 365

Security

Problem: Without central device management, compliance control and enforceable security policies are missing.

Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations

Result: Existing endpoints centrally managed — the foundation for all further scenarios.

Icon
Intune Device Enrollment

Microsoft 365

Security

Problem: Without central device management, compliance control and enforceable security policies are missing.

Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations

Result: Existing endpoints centrally managed — the foundation for all further scenarios.

Icon
Intune Autopilot

Microsoft 365

Security

Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.

Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices

Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.

Icon
Intune Autopilot

Microsoft 365

Security

Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.

Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices

Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.

Icon
Privileged Identity Management

Microsoft 365

Security

Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.

Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM

Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.

Icon
Privileged Identity Management

Microsoft 365

Security

Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.

Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM

Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.

In 30 minutes we will show you the blueprint for your specific use case.

Start a Blueprint.

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case.

Start a Blueprint.

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case.

Start a Blueprint.

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case.

Start a Blueprint.

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH