
Intune LAPS
Unique, rotating local admin passwords on every Windows device. Backed up to Entra ID. No more shared secret that opens every laptop.
One Local Admin Password on Every Device Is Always on Every Device
On most mid-market Windows devices, the local administrator password is the same. It was set during imaging five years ago. It is written in a password manager. It is shared with the helpdesk. One phished credential, one stolen laptop, and an attacker has the key to every other device — classic lateral movement.
This is not a failure of your IT team. Legacy Microsoft LAPS needed on-prem AD, GPO, a schema extension, an MSI agent, and careful maintenance. Windows LAPS changed that: it ships in Windows 11 — out of the box from 23H2, and from the April 2023 update on 21H2 and 22H2 — is managed via Intune, and backs up to Entra ID. The license is already yours. What is missing: the policy design, the migration from legacy Microsoft LAPS or static passwords, and the operational runbook.
Traditional consulting for LAPS? Five figures. The consultant configures, leaves a document, leaves. Your helpdesk is back to sharing a password next time somebody new joins.
ACTIVITIES IN DETAIL
DELIVERABLES
Prerequisites: Intune licensing, Windows builds, April 2023 update, enrollment and sync state
Current State: Static shared passwords, legacy Microsoft LAPS, and unmanaged devices
Target Design: Backup directory, managed account, complexity, rotation interval, and reset delay
Retrieval Access: Who retrieves a password and which role they hold, built-in or least-privilege
Tenant and Policy: Windows LAPS enabled, Intune policy created, conflicting policies ruled out
Pilot: 3-5 devices checked for backup, retrieval, login, and post-authentication rotation
Rollout and Retirement: All target groups monitored, legacy GPO unlinked and MSI uninstalled
Next steps after Intune LAPS
A cleanly configured tenant is the foundation. These blueprints build directly on it




