# Set up Windows LAPS on Windows Server 2025 and Windows 11

Source: https://srvscripts.com/guides/windows-laps-setup/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Windows LAPS is the built-in successor to the legacy Local Administrator Password Solution. It is part of Windows 11 (22H2 and later), Windows Server 2022 with the April 2023 update and Windows Server 2025 out of the box, so there is nothing to install on clients; you extend the schema, delegate rights, and push a policy. Each managed machine then rotates its local administrator password on a schedule and stores it, encrypted, on its own computer object in Active Directory, where only the groups you delegate can read it. This guide covers the on-premises Active Directory mode; the Entra ID mode uses Intune policy instead.

In short: As a Schema Admin run Update-LapsADSchema once, grant computers the right to write their own password with Set-LapsADComputerSelfPermission -Identity “OU=Workstations,DC=corp,DC=example,DC=com”, grant helpdesk read rights with…

**Short answer:** As a Schema Admin run `Update-LapsADSchema` once, grant computers the right to write their own password with `Set-LapsADComputerSelfPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com"`, grant helpdesk read rights with `Set-LapsADReadPasswordPermission`, then enable the policy under Computer Configuration » Policies » Administrative Templates » System » LAPS with the backup directory set to Active Directory. Read a password with `Get-LapsADPassword -Identity PC01 -AsPlainText` and force a rotation with `Reset-LapsPassword` on the client.

## Extend the schema and delegate permissions

The LAPS PowerShell module is present on any Windows Server 2025 DC and on Windows 11 with RSAT. Extend the schema from a machine that can reach the Schema Master, as a member of Schema Admins:

```
Import-Module LAPS
Update-LapsADSchema -Verbose
```

This adds attributes including `msLAPS-Password`, `msLAPS-EncryptedPassword`, `msLAPS-PasswordExpirationTime` and the DSRM equivalents. Next, allow computers in the target OUs to write their own password attributes, and allow a helpdesk group to read them:

```
Set-LapsADComputerSelfPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com"
Set-LapsADComputerSelfPermission -Identity "OU=Servers,DC=corp,DC=example,DC=com"
Set-LapsADReadPasswordPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com" -AllowedPrincipals "CORP\Helpdesk"
Set-LapsADResetPasswordPermission -Identity "OU=Workstations,DC=corp,DC=example,DC=com" -AllowedPrincipals "CORP\Helpdesk"
```

Before delegating, find out who already has “All extended rights” on those OUs, because that right includes reading the password attributes. `Find-LapsADExtendedRights -Identity "OU=Workstations,DC=corp,DC=example,DC=com"` lists them; remove anything unexpected in Active Directory Users and Computers under the OU’s Advanced Security settings.

## Configure the policy with Group Policy

Create a GPO linked to the workstation and server OUs. The settings live under Computer Configuration » Policies » Administrative Templates » System » LAPS (the ADMX is included in Windows Server 2025 and Windows 11; for an older central store copy `LAPS.admx` from a Windows 11 machine). Set at least:

- Configure password backup directory: Enabled, Active Directory

- Password Settings: Enabled, complexity “Large letters + small letters + numbers + special characters”, length 20, age 30 days

- Name of administrator account to manage: only if you renamed the built-in account; otherwise leave blank and LAPS manages the built-in RID 500 account

- Post-authentication actions: Enabled, “Reset the password and log off the managed account” with a grace period of 24 hours, so a password used by the helpdesk is automatically rotated afterwards

- Enable password encryption: Enabled (requires the domain functional level to be 2016 or higher); optionally set “Configure authorized password decryptors” to the helpdesk group

Run `gpupdate /force` on a test machine and check the Application and Services Logs » Microsoft » Windows » LAPS » Operational log for Event ID 10018 (policy processed) and 10020 (password updated). If you still have the legacy LAPS CSE installed, Windows LAPS will refuse to manage the same account until the legacy policy is removed; Event 10033 signals this conflict.

## Retrieve, rotate and audit passwords

From a workstation or server with the module:

```
Get-LapsADPassword -Identity "PC-FINANCE-07" -AsPlainText
Get-LapsADPassword -Identity "PC-FINANCE-07" -IncludeHistory
Set-LapsADPasswordExpirationTime -Identity "PC-FINANCE-07"
```

Setting the expiration time to now makes the client rotate at its next policy refresh, or run `Reset-LapsPassword` locally to do it immediately. The Active Directory Users and Computers console also shows a LAPS tab on each computer object on Windows Server 2025, with the password, expiry and a button to expire it. Every read is recorded as Event ID 4662 on the DC with the reader’s identity if “Audit Directory Service Access” is enabled, which is worth forwarding to your SIEM.

## Verify

On the client, `Get-LapsDiagnostics` collects logs, and `Get-LapsADPassword` from a delegated account must return a password with an expiry date in the future. Try the same read as a user outside the delegated group and expect an access denied error. A common pitfall is applying the policy to the Domain Controllers OU; LAPS on a DC manages the DSRM account instead, which is a separate setting (“Enable DSRM password backup”) and should be decided deliberately, not inherited from a workstation policy.

## Windows LAPS at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows client documentation](https://learn.microsoft.com/en-us/windows/), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Fix “Invalid Signature Detected: Check Secure Boot Policy”](https://srvscripts.com/guides/invalid-signature-detected-secure-boot/) · [Offboarding an employee: checklist for Active Directory, Microsoft 365, Google Workspace and Zoho](https://srvscripts.com/guides/employee-offboarding-checklist/) · [Disable RDP drive, clipboard and USB redirection with Group Policy](https://srvscripts.com/guides/disable-rdp-drive-redirection-gpo/).

## Frequently asked questions

### Does Windows LAPS also work on Windows 10 or Windows Server 2019?

Yes, on Windows 10 and Server 2019 with the April 2023 or later cumulative update; the schema extension and policy are the same, but older builds need the LAPS ADMX copied into the central store.

### How long does it take for LAPS to set the first password after the policy applies?

The client processes the policy at the next Group Policy refresh, usually within 90 minutes, and sets the password immediately if none exists; a `gpupdate /force` followed by `Invoke-LapsPolicyProcessing` makes it happen at once.

### Can I undo Windows LAPS once it is deployed?

You can unlink the GPO and the clients stop rotating, but the schema extension is permanent and the last stored password stays on each computer object until you clear the attributes, so treat the delegation as ongoing even if you stop using the feature.
