Local Admin Password Solution
If a single password is configured for the local admin accounts across all domain-joined computers, there is a high risk that it can be used in a widespread attack to install malware, elevate privileges, or gain access to sensitive files. To resolve this issue, Microsoft offers the Local Admin Password Solution (LAPS). This works by setting a different random password on every computer in the domain and storing that password in AD. Administrators can choose who can access those passwords in order to support the PCs.
The solution is built into AD and doesn't require any other supporting technologies or licenses. LAPS uses the Group Policy client-side extension (CSE) that you install on managed computers to perform ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access