Short answer: To back up local admin passwords to Microsoft Entra ID, first turn on Enable Local Administrator Password Solution (LAPS) in Entra ID > Devices > Device settings, then create an Intune policy under Endpoint security > Account protection > Local admin password solution (Windows LAPS) with Backup Directory set to Microsoft Entra ID, and assign it to device groups. Retrieve passwords in the Intune or Entra admin center, or with Get-LapsAADPassword -DeviceIds <name> -IncludePasswords -AsPlainText after Connect-MgGraph with the DeviceLocalCredential.Read.All permission. Legacy Microsoft LAPS is deprecated and blocked on Windows 11 23H2 and later, so migrate to the built-in Windows LAPS.
Commands checked against the official documentation (linked below) on 6 October 2026; not yet run on our lab servers.
Table of Contents
When to use Entra ID backup instead of Active Directory
Windows LAPS is built into Windows and can store the managed password in either on-premises Active Directory or Microsoft Entra ID, never both for the same policy. Our Windows LAPS setup guide covers the Active Directory side (schema, Group Policy, Get-LapsADPassword). This guide covers Entra ID backup through Intune, which is the right choice when:
- Devices are Microsoft Entra joined (cloud-only), with no domain controller to store passwords.
- Devices are hybrid joined, but your helpdesk works from Intune and the Entra admin center rather than AD tools.
- You want Entra audit logs, Conditional Access and administrative units around who can read passwords.
Requirements from Microsoft:
- Microsoft Entra joined or Microsoft Entra hybrid joined devices. Entra registered devices (BYOD workplace join) are not supported.
- Windows 11 23H2 and later, or Windows 10 20H2/21H2/22H2, Windows 11 21H2/22H2, Windows Server 2019 and 2022 with the April 11, 2023 update or later. Windows Server 2025 includes it.
- Any Microsoft Entra ID licence, including Free, for the LAPS feature itself. Intune, custom roles, administrative units and Conditional Access have their own licensing.
Step 1: enable LAPS in the Entra tenant
By default Entra ID refuses password uploads from devices. Sign in to the Microsoft Entra admin center as at least a Cloud Device Administrator, go to Entra ID > Devices > Device settings, set Enable Local Administrator Password Solution (LAPS) to Yes and save.
Then review who can read passwords. Built-in roles such as Cloud Device Administrator and Intune Administrator can recover them, and these roles are highly privileged. For a helpdesk, Microsoft supports a custom role with the microsoft.directory/deviceLocalCredentials/password/read permission, or Cloud Device Administrator scoped to an administrative unit that contains only the devices that team supports.
Step 2: create the Intune LAPS policy
- Intune admin center > Endpoint security > Account protection > Create Policy.
- Platform Windows, profile Local admin password solution (Windows LAPS).
- Backup Directory: choose the Microsoft Entra ID (Azure AD) option. The directory must match the device join type: an Entra-joined device given an Active Directory backup policy applies the settings but can never back up.
- Set Password Age Days, Password Complexity and Password Length to match your policy.
- Leave Administrator Account Name empty to manage the built-in Administrator (found by its well-known RID, whatever its localized name), or enter the name of a custom account. Windows LAPS does not create accounts: create a custom account first, for example with the Accounts CSP.
- Set Post Authentication Actions and Post Authentication Reset Delay so the password rotates (and optionally the session is signed out) a few hours after someone uses it.
- Assign the policy to device groups. Microsoft recommends device groups because user-targeted LAPS policy follows the user and can produce inconsistent behaviour.
Only these settings apply in Entra mode: BackupDirectory, PasswordAgeDays, PasswordComplexity, PasswordLength, AdministratorAccountName, PostAuthenticationResetDelay and PostAuthenticationActions. AD-only settings such as password encryption are ignored.
Make sure each device gets exactly one LAPS policy. The Windows LAPS CSP supports a single value per setting, and conflicting Intune policies can stop the device processing LAPS and backing up its password. Intune CSP settings also take precedence over LAPS Group Policy on the same device.
Step 3: confirm the device backed up its password
Windows LAPS processes policy every hour. On a test device, force it and read the LAPS event log:
Invoke-LapsPolicyProcessing
Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 20 |
Format-Table TimeCreated, Id, LevelDisplayName, Message -Wrap
Event 10029 confirms the password was successfully updated in Microsoft Entra ID. When a Windows LAPS policy first applies, the device rotates the account password immediately.
In Intune, open the device and select Local admin password to see the account name, last rotation and next rotation time. Data appears only after the device has checked in and processed the policy.
Step 4: retrieve passwords
In the portals
In the Intune admin center open Devices, select the device and open its Local admin password page; in the Entra admin center open the device under Devices and use its local administrator password recovery page. Microsoft notes that viewing a password triggers an audit event, so every recovery is traceable.
With PowerShell
The Get-LapsAADPassword cmdlet ships with Windows LAPS and calls Microsoft Graph for you. It needs the Microsoft Graph PowerShell SDK and an Entra app registration with Device.Read.All plus DeviceLocalCredential.Read.All (passwords) or DeviceLocalCredential.ReadBasic.All (metadata only: backup and expiry times). Use ReadBasic for reporting; Read.All exposes clear-text passwords.
Install-Module Microsoft.Graph -Scope AllUsers
# Sign in with your app registration (delegated); use your own tenant and app IDs
Connect-MgGraph -Environment Global -TenantId 00000000-0000-0000-0000-000000000000 -ClientId 11111111-1111-1111-1111-111111111111
# Metadata only (ReadBasic is enough)
Get-LapsAADPassword -DeviceIds PC-0142
# Password as a SecureString
Get-LapsAADPassword -DeviceIds PC-0142 -IncludePasswords
# Clear text, for ad-hoc helpdesk use only
Get-LapsAADPassword -DeviceIds PC-0142 -IncludePasswords -AsPlainText
-DeviceIds accepts the device name or its Entra device ID. -IncludeHistory also returns previous passwords still stored for that device, which you need after restoring a machine from an older backup.
Without the LAPS module (for example from a non-Windows automation host), call Graph directly: GET https://graph.microsoft.com/v1.0/directory/deviceLocalCredentials/{deviceId}?$select=credentials. The response lists credentials with accountName, backupDateTime and a base64-encoded passwordBase64. Microsoft marks the User-Agent header as required for this call.
Rotate after use
Rotate a password on demand from Intune (Devices > device > Rotate local admin password, which needs specific Intune permissions), or locally on the device with Reset-LapsPassword. Microsoft notes that, unlike AD-backed LAPS, you cannot force a rotation by editing the expiry time in Entra ID, and very frequent resets may be throttled.
Migrate from legacy Microsoft LAPS
Legacy Microsoft LAPS (the AdmPwd MSI and Group Policy extension) is deprecated as of Windows 11 23H2, and newer Windows versions block its installer. Microsoft documents two migration approaches:
| Approach | Steps |
|---|---|
| Immediate transition | Disable the legacy LAPS GPO and apply the Windows LAPS policy at the same time, targeting the same account; confirm the new password is backed up; then uninstall the legacy LAPS MSI. |
| Side-by-side, then switch | Create a second local account; point Windows LAPS at it; confirm it works; remove the legacy policy and software; delete the extra account. |
Legacy LAPS and Windows LAPS must never manage the same account at the same time. Moving from AD-stored legacy passwords to Entra ID also changes where your helpdesk looks, so update runbooks and access rights in the same change.
Hybrid note: Windows LAPS does not use Microsoft Entra Connect. Devices upload to Entra ID directly over HTTPS, and syncing on-premises LAPS attributes to Entra is not a tested scenario and will not show passwords in the portals.
Check that it worked
- Test devices log event 10029 and show a last rotation time in Intune.
Get-LapsAADPassword -DeviceIds <name>returns a recent backup time for a sample of devices from each group.- A helpdesk account with only your custom role can read passwords for its scoped devices and nothing else.
- The Entra audit log records each password recovery.
- Legacy LAPS GPOs are unlinked and the AdmPwd software is gone from migrated devices.
Official documentation: Get started with Windows LAPS and Microsoft Entra ID · Manage Windows LAPS policy with Intune · Windows LAPS in Microsoft Entra ID · Migrate to Windows LAPS from legacy LAPS
Related: Set up Windows LAPS on Windows Server 2025 and Windows 11 · Local Administrators Group Policy: 4 Ways to Control Admin Rights · Intune Bulk Enrollment: Windows 11 Provisioning Package · Employee Offboarding Checklist: Secure AD, M365 and Workspace Steps · Secure Password Generator
See also: Microsoft 365 MFA Status Report: PowerShell Script for Graph · Entra ID Inactive Users Report: signInActivity PowerShell Script · Intune Device Compliance Report: PowerShell Script via Graph · Microsoft 365 User Offboarding PowerShell Script (with -WhatIf)
Frequently asked questions
Can Windows LAPS back up to both Active Directory and Entra ID?
No. Each policy has one Backup Directory. Hybrid-joined devices can use either, but not both at once.
Does Windows LAPS create the local admin account?
No. It manages the built-in Administrator by default, or an existing account you name. Create custom accounts first, for example with the Accounts CSP.
Which Graph permission do I need to read LAPS passwords?
DeviceLocalCredential.Read.All for passwords, plus Device.Read.All. DeviceLocalCredential.ReadBasic.All only returns metadata such as backup and expiry times.
Why does Intune show no LAPS data for a device?
Usually the tenant setting is off, the device has not checked in since the policy was assigned, the device is Entra registered rather than joined, or two LAPS policies conflict.
Can I still install legacy Microsoft LAPS on Windows 11?
Not on Windows 11 23H2 and later, where the installer is blocked. Use the built-in Windows LAPS.