Windows LAPS is the built-in successor to the legacy Local Administrator Password Solution. It is part of Windows 11 (22H2 and later), Windows Server 2022 with the April 2023 update and Windows Server 2025 out of the box, so there is nothing to install on clients; you extend the schema, delegate rights, and push a policy. Each managed machine then rotates its local administrator password on a schedule and stores it, encrypted, on its own computer object in Active Directory, where only the groups you delegate can read it. This guide covers the on-premises Active Directory mode; the Entra ID mode uses Intune policy instead.
Table of Contents
Short answer: As a Schema Admin run Update-LapsADSchema once, grant computers the right to write their own password with Set-LapsADComputerSelfPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com", grant helpdesk read rights with Set-LapsADReadPasswordPermission, then enable the policy under Computer Configuration » Policies » Administrative Templates » System » LAPS with the backup directory set to Active Directory. Read a password with Get-LapsADPassword -Identity PC01 -AsPlainText and force a rotation with Reset-LapsPassword on the client.
Extend the schema and delegate permissions
The LAPS PowerShell module is present on any Windows Server 2025 DC and on Windows 11 with RSAT. Extend the schema from a machine that can reach the Schema Master, as a member of Schema Admins:
Import-Module LAPS
Update-LapsADSchema -Verbose
This adds attributes including msLAPS-Password, msLAPS-EncryptedPassword, msLAPS-PasswordExpirationTime and the DSRM equivalents. Next, allow computers in the target OUs to write their own password attributes, and allow a helpdesk group to read them:
Set-LapsADComputerSelfPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com"
Set-LapsADComputerSelfPermission -Identity "OU=Servers,DC=corp,DC=example,DC=com"
Set-LapsADReadPasswordPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com" -AllowedPrincipals "CORP\Helpdesk"
Set-LapsADResetPasswordPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com" -AllowedPrincipals "CORP\Helpdesk"
Before delegating, find out who already has “All extended rights” on those OUs, because that right includes reading the password attributes. Find-LapsADExtendedRights -Identity "OU=Workstations,DC=corp,DC=example,DC=com" lists them; remove anything unexpected in Active Directory Users and Computers under the OU’s Advanced Security settings.
Configure the policy with Group Policy
Create a GPO linked to the workstation and server OUs. The settings live under Computer Configuration » Policies » Administrative Templates » System » LAPS (the ADMX is included in Windows Server 2025 and Windows 11; for an older central store copy LAPS.admx from a Windows 11 machine). Set at least:
- Configure password backup directory: Enabled, Active Directory
- Password Settings: Enabled, complexity “Large letters + small letters + numbers + special characters”, length 20, age 30 days
- Name of administrator account to manage: only if you renamed the built-in account; otherwise leave blank and LAPS manages the built-in RID 500 account
- Post-authentication actions: Enabled, “Reset the password and log off the managed account” with a grace period of 24 hours, so a password used by the helpdesk is automatically rotated afterwards
- Enable password encryption: Enabled (requires the domain functional level to be 2016 or higher); optionally set “Configure authorized password decryptors” to the helpdesk group
Run gpupdate /force on a test machine and check the Application and Services Logs » Microsoft » Windows » LAPS » Operational log for Event ID 10018 (policy processed) and 10020 (password updated). If you still have the legacy LAPS CSE installed, Windows LAPS will refuse to manage the same account until the legacy policy is removed; Event 10033 signals this conflict.
Retrieve, rotate and audit passwords
From a workstation or server with the module:
Get-LapsADPassword -Identity "PC-FINANCE-07" -AsPlainText
Get-LapsADPassword -Identity "PC-FINANCE-07" -IncludeHistory
Set-LapsADPasswordExpirationTime -Identity "PC-FINANCE-07"
Setting the expiration time to now makes the client rotate at its next policy refresh, or run Reset-LapsPassword locally to do it immediately. The Active Directory Users and Computers console also shows a LAPS tab on each computer object on Windows Server 2025, with the password, expiry and a button to expire it. Every read is recorded as Event ID 4662 on the DC with the reader’s identity if “Audit Directory Service Access” is enabled, which is worth forwarding to your SIEM.
Verify
On the client, Get-LapsDiagnostics collects logs, and Get-LapsADPassword from a delegated account must return a password with an expiry date in the future. Try the same read as a user outside the delegated group and expect an access denied error. A common pitfall is applying the policy to the Domain Controllers OU; LAPS on a DC manages the DSRM account instead, which is a separate setting (“Enable DSRM password backup”) and should be decided deliberately, not inherited from a workstation policy.
Windows LAPS at a glance

Official documentation: Active Directory Domain Services docs, Windows client documentation, Windows Server documentation.
Related guides: Fix “Invalid Signature Detected: Check Secure Boot Policy” · Offboarding an employee: checklist for Active Directory, Microsoft 365, Google Workspace and Zoho · Disable RDP drive, clipboard and USB redirection with Group Policy.
Frequently asked questions
Does Windows LAPS also work on Windows 10 or Windows Server 2019?
Yes, on Windows 10 and Server 2019 with the April 2023 or later cumulative update; the schema extension and policy are the same, but older builds need the LAPS ADMX copied into the central store.
How long does it take for LAPS to set the first password after the policy applies?
The client processes the policy at the next Group Policy refresh, usually within 90 minutes, and sets the password immediately if none exists; a gpupdate /force followed by Invoke-LapsPolicyProcessing makes it happen at once.
Can I undo Windows LAPS once it is deployed?
You can unlink the GPO and the clients stop rotating, but the schema extension is permanent and the last stored password stays on each computer object until you clear the attributes, so treat the delegation as ongoing even if you stop using the feature.