
Intune LAPS
Einzigartige, rotierende lokale Administratorpasswörter auf jedem Windows-Gerät. Gesichert in Entra ID. Kein gemeinsames Geheimnis mehr, das jeden Laptop entsperrt.
One Local Admin Password on Every Device Is Always on Every Device
On most mid-market Windows devices, the local administrator password is the same. It was set during imaging five years ago. It is written in a password manager. It is shared with the helpdesk. One phished credential, one stolen laptop, and an attacker has the key to every other device — classic lateral movement.
This is not a failure of your IT team. The old Microsoft LAPS needed on-prem AD, GPO, a schema extension, and careful maintenance. Windows LAPS changed that: it is built into Windows 11 and Windows 10 22H2, managed via Intune, and backs up to Entra ID. The license is already yours. What is missing: the policy design, the migration from legacy LAPS or static passwords, and the operational runbook.
Traditional consulting for LAPS? Five figures. The consultant configures, leaves a document, leaves. Your helpdesk is back to sharing a password next time somebody new joins.
AKTIVITÄTEN IM DETAIL
LIEFERUMFANG
Voraussetzungen überprüfen: Intune Plan 1, Entra ID Free, Windows 11 22H2+ oder Windows 10 22H2 mit KB5025221
Windows LAPS in den Entra ID Tenant-Einstellungen aktivieren (Entra Admin Center → Geräte → Geräteeinstellungen)
Bestandsaufnahme des aktuellen Status der lokalen Administratoren: statische Kennwörter, Legacy-Microsoft LAPS, GPO-basiertes LAPS, nicht verwaltete Geräte
Intune LAPS-Richtlinie entwerfen: Zielkonto (integrierte RID oder benanntes Konto), Kennwortkomplexität, Länge (14–64 Zeichen), Rotationsplan (30–90 Tage)
Backup-Verzeichnis auswählen: Entra ID (empfohlen für Cloud- oder Hybrid-Inbound-Verbindungen), lokales AD (nur für Domänenbeitritt)
Rollenbasierte Zugriffskontrolle: Welche Intune-Admins Kennwörter lesen und rotieren können — Endpoint Security Manager-Rolle
Bereitstellung in der Pilotgerätegruppe (10–20 Geräte), Backup im Intune Admin Center validieren, manuelle Rotation testen
Gestaffelter Rollout nach Gerätegruppe — Welle für Welle, mit Compliance-Überwachung
Deaktivierung von Legacy-LAPS: GPO-Entfernung, Deinstallation von Legacy-MS LAPS, Bereinigung des Kennworttresors
Helpdesk-Runbook: Abrufen eines aktuellen Kennworts, manuelle Rotation, Fehlerbehebung bei Backup-Fehlern
Nächste Schritte nach Intune LAPS
Ein sauber konfigurierter Tenant ist die Grundlage. Diese Blueprints bauen direkt darauf auf.




