Comments on: How to Configure Group Policy for LAPS https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/ SCCM | ConfigMgr | Intune | Windows 11 | Azure Wed, 06 Oct 2021 17:21:53 +0000 hourly 1 https://wordpress.org/?v=6.4.1 By: Rob https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-28353 https://www.prajwaldesai.com/?p=13305#comment-28353 In reply to Scott Wojtowicz.

You will need to import it..
First install the LAPS Software from the Microsoft site. Next go to: C:\Windows\PolicyDefinitions and copy:
AdmPWD.admx
Paste it in: C:\Windows\SysVol\domain\policies\PolicyDefinitions
next copy AdmPWD.ADML from the C:\Windows\PolicyDefinitions\en-us
Into: C:\Windows\SYSVOL\domain\Policies\PolicyDefinitions\en-US
Refresh your Group Policy console and reopen the GPO you will see it listed under the Computer configuration\Administrative templates\LAPS

]]>
By: Scott Wojtowicz https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-23578 https://www.prajwaldesai.com/?p=13305#comment-23578 When I go to add the GP, LAPS is not included in the Administrative Templates. How do I install it?

]]>
By: Asif Nasar https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-17136 https://www.prajwaldesai.com/?p=13305#comment-17136 Hi Prajwal

Very insightful guide. Thank you.

I am having ONE major problem after implementing this in my work environment.

The ONE attribute ms-Mcs-AdmPwdExpirationTime registers changes when i check against the computer attribute, HOWEVER, the ms-Mcs-AdmPwd does not, and the LAPS GUI reports back that the password has been reset successfuly, when it has not?

Any ideas pls?

Would really appreciate your help.

Thank you

Kind Regards

]]>
By: Michael Cooper https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-16940 https://www.prajwaldesai.com/?p=13305#comment-16940 In reply to NotYourRegularJoe.

I am not sure if this applies but from what I gather from this it randomly resets the local admin password and you use the LAPS UI to get that password. I believe it would be the Administrator account for the local machine. I could be wrong.
Michael

]]>
By: Ajay https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-12983 https://www.prajwaldesai.com/?p=13305#comment-12983 If computer is out of network for very long time and rarely visits corporate network, how the password is getting changed in that case.

]]>
By: Christian https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-12137 https://www.prajwaldesai.com/?p=13305#comment-12137 In reply to Elvis.

I thought this exactly so I created my policies where my computers, laptops, tablets etc. are stored – nowhere near any of my servers.

]]>
By: Elvis https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-9298 https://www.prajwaldesai.com/?p=13305#comment-9298 It is not the best way to apply GPO to the domain.
Use dedicated OU for applying LAPS. I think that some servers like DCs should not be a part LAPS clients. Of course another reason is because you need test before you apply LAPS to entire organization – and apply GPO to entire domain is wrong once again. Be careful!

]]>
By: NotYourRegularJoe https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-7461 https://www.prajwaldesai.com/?p=13305#comment-7461 Hi Prajwal, I tried this and completed the setups as per your guides, when I lookup a password I do get a value but for what account will that be? Not sure I understand this very las t part, I thought it would be the local Administrator account, I set a predefined password manually but the results are different, Tried using the password from LAPS with Administrator user name and it wouldn’t log me in. Can you assist?

]]>
By: NotYourRegularJoe https://www.prajwaldesai.com/how-to-configure-group-policy-for-laps/#comment-7459 https://www.prajwaldesai.com/?p=13305#comment-7459 Hi Prajwal, I tried this and completed the setups as per your guides, when I lookup a password I do get a value but for what account will that be? Not sure I understand this very las t part, I thought it would be the local Administrator account, I set a predefined password manually but the results are different, Tried using the password from LAPS with Administrator user name and it wouldn’t log me in. Can you assist?

]]>