ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What are your Thoughts on Using LAPS to manage local admin account passwords on a domain?

    IT Discussion
    5
    7
    613
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      ElecEng
      last edited by

      What are your thoughts on Using LAPS to manage local admin account passwords on a domain?

      jclambertJ ObsolesceO PhlipElderP 3 Replies Last reply Reply Quote 0
      • jclambertJ
        jclambert @ElecEng
        last edited by

        @eleceng
        The basic premise of helping to stop horizontal attacks is wonderful. Last year we reviewed this as an option. In a test, it implemented well enough, but the PW was not truly encrypted. This can be better explained here:
        https://techgenix.com/case-against-using-laps/amp/

        ObsolesceO 1 Reply Last reply Reply Quote 3
        • DashrenderD
          Dashrender
          last edited by

          I like this thinking - I wonder what the solution is for a no AD, but only AAD setup is?
          Is this something Intune can handle? Some other MS service?

          1 Reply Last reply Reply Quote 0
          • ObsolesceO
            Obsolesce @ElecEng
            last edited by

            @eleceng said in What are your Thoughts on Using LAPS to manage local admin account passwords on a domain?:

            What are your thoughts on Using LAPS to manage local admin account passwords on a domain?

            Are these local admin accounts on servers or user devices?

            E 1 Reply Last reply Reply Quote 0
            • ObsolesceO
              Obsolesce @jclambert
              last edited by

              @jclambert said in What are your Thoughts on Using LAPS to manage local admin account passwords on a domain?:

              The basic premise of helping to stop horizontal attacks is wonderful

              But the device is joined to an AD domain so horizontal attacks are allowed by default.

              1 Reply Last reply Reply Quote 0
              • PhlipElderP
                PhlipElder @ElecEng
                last edited by

                @eleceng said in What are your Thoughts on Using LAPS to manage local admin account passwords on a domain?:

                What are your thoughts on Using LAPS to manage local admin account passwords on a domain?

                Use it. It's excellent.

                Tie in DUO for 2FA on critical infrastructure like DCs and the backup server(s) and good to go.

                1 Reply Last reply Reply Quote 1
                • E
                  ElecEng @Obsolesce
                  last edited by

                  @obsolesce Servers primarily but user desktops and laptops will be the same.

                  1 Reply Last reply Reply Quote 0
                  • 1 / 1
                  • First post
                    Last post