Type something to search...
How to enable LAPS on the MTR Admin account via Intune

How to enable LAPS on the MTR Admin account via Intune


Definition

Microsoft’s LAPS (Local Administrator Password Solution) is a free tool designed to improve password security for local administrator accounts on workstations, servers and also Microsoft Teams conference rooms.


How does LAPS work ?

LAPS automatically generates unique and complex passwords for the local administrator accounts of each managed machine. These passwords are then securely stored in Intune. Here are the key steps in its operation :

  • Password generation : LAPS creates random passwords for local administrator accounts according to complexity criteria defined by the administrator.
  • Secure storage : Generated passwords are stored in Intune.
  • Controlled access : Only users with appropriate permissions can access passwords. This ensures that they are only accessible to authorized administrators.
  • Automatic rotation : LAPS allows you to set password rotation policies, ensuring that passwords are regularly updated to strengthen security.

Why implement LAPS?
  • Reinforced security : Using the same local administrator password on several machines is a risky practice. If an attacker manages to obtain this password, they can move laterally within the network. LAPS eliminates this risk by generating unique passwords for each machine.
  • Simplified management : LAPS automates the management of local administrator passwords, reducing the workload of system administrators. No more manually managing passwords or storing them in insecure files.
  • Compliance : Many security regulations require secure password management. LAPS helps organizations comply with these requirements by providing centralized and secure password management.

Prerequisites

Licenses required

  • Teams Rooms Pro (or Basic).

A Teams room

  • A Windows MTR deployed.

Administrator role

  • An account with the Global Administrator or User Administrator role to access the Microsoft Entra Admin Center.
  • An account with the Global Administrator or Intune Administrator role to access the Microsoft Intune Admin Center.

Step 1 : Sign in to the Microsoft Entra Admin Center

Sign in to the Microsoft Entra Admin Center by opening your web browser to https://entra.microsoft.com.


Step 2 : Enable LAPS

In the left menu, click Identity, then Devices and All devices.

Click Device settings, then click the Enable Entra Local Administrator Password Solution (LAPS) switch to enable the service.

image


Step 3 : Create a security group

In the left menu, click Identity, then Groups and All groups.

Click New group to create a new security group of type Dynamic device.

image

Click Add dynamic query, then add (device.displayName -startsWith “MTR-”) to the rule. This will make it possible to bring together all the MTRs in the same group.

image


Step 4 : Sign in to the Microsoft Intune Admin Center

Sign in to the Microsoft Intune Admin Center by opening your web browser to https://intune.microsoft.com.


Step 5 : Create a LAPS rule

In the left menu, click Endpoint security, then Account protection.

Create a rule for the Windows 10 and later platform with the Local admin password solution (Windows LAPS) profile.

image

Enable the options with the values ​​of your choice.
We want to target the Admin account (whose default password is sfb) of the MTR.

image

Assign the security group created in step 3.

image


Step 6 : Access the password

In the left menu, click Devices, then find the MTR you want to check.

image

Click Show local administrator password to reveal its temporary password.

image

Below, you can see when the password was automatically changed for the last time, and when it will be replaced again.


Step 7 : Validate the logs

From the Windows interface (with the new password), go to the Event Viewer and open the Applications and Services Logs / Microsoft / Windows / LAPS directory. The logs will be visible.

image


Let’s go further

The procedure here is presented for a Teams MTR conference room whose default account is Admin and comes with the password sfb, but it also works for the local administrator accounts of your users’ workstations.


Conclusion

Implementing LAPS is a crucial step in strengthening the security of local administrator accounts in an organization. By automating password generation and management, LAPS reduces security risks and simplifies the work of system administrators. By following the steps outlined, you can implement LAPS effectively and improve the security of your infrastructure.

You now know how to activate LAPS on the MTR Admin account.


Sources

Microsoft Learn - Windows LAPS


Did you enjoy this post ? If you have any questions, comments or suggestions, please feel free to send me a message from the contact form.

Don’t forget to follow us and share this post.

Related Posts

Digital signage with Teams Rooms

Digital signage with Teams Rooms

Introduction Microsoft Teams continues to innovate to offer increasingly effective communication and collaboration solutions. Among the recent features, digital signage in Teams Rooms ext

Read More
Email verification of external Teams participants

Email verification of external Teams participants

Introduction Microsoft Teams Premium introduces a new feature to enhance the security and reliability of your meetings: email verification for external participants. This feature allows mee

Read More
Migrating Android Teams devices to AOSP

Migrating Android Teams devices to AOSP

Introduction Microsoft announced a major migration for Android-based Microsoft Teams devices, such as phones, conference rooms, and panels. This migration consists of moving from the *Devic

Read More
How to activate Microsoft 365 Passkey in Entra ID

How to activate Microsoft 365 Passkey in Entra ID

Definition Microsoft 365 Passkey is an authentication method that replaces passwords with more secure options like facial recognition, fingerprint, or a PIN.Prerequisites **

Read More
How to sign in with Passkey to Microsoft 365

How to sign in with Passkey to Microsoft 365

Definition Microsoft 365 Passkey is an authentication method that replaces passwords with more secure options like facial recognition, fingerprint, or a PIN.Prerequisites **

Read More
End of support for Teams Rooms on Windows 10

End of support for Teams Rooms on Windows 10

Introduction Microsoft has announced the end of support for the latest version of Windows 10 (22H2 - version 10.0.19045) on Teams Rooms, effective October 14, 2025. This decision marks an i

Read More
Multi-camera view in the Teams Rooms on Windows

Multi-camera view in the Teams Rooms on Windows

Introduction Microsoft continues to innovate to improve the user experience in Microsoft Teams Rooms. One of the latest features introduced is the multi-camera view, available on Teams Room

Read More
How to enable remote access to MTR via Teams Rooms Pro

How to enable remote access to MTR via Teams Rooms Pro

Definition The Microsoft Teams Room Pro Management portal is a powerful solution designed to help administrators effectively monitor and manage meeting rooms equipped with Microsoft Teams

Read More
How to migrate your Android Teams devices to AOSP

How to migrate your Android Teams devices to AOSP

Introduction I told you last November about the approach to migrating to AOSP (Android Open Source Project) for Android-based Microsoft Teams devices, such as phones, conference rooms a

Read More
New Yealink MeetingBoard 65 and 85 for Teams rooms

New Yealink MeetingBoard 65 and 85 for Teams rooms

Introduction The new Yealink MeetingBoard 65 and 85 are an innovative and comprehensive solution designed to transform meeting rooms into intelligent collaboration spaces. These all-in-on

Read More
How to enable password writeback in Entra ID

How to enable password writeback in Entra ID

Introduction In an organization configured as hybrid with Microsoft cloud, user accounts are created in the on-premises Active Directory and are synchronized with Microsoft Entra ID. In

Read More
How to update your Android Teams devices to AOSP

How to update your Android Teams devices to AOSP

Introduction I wrote an article last February on how to prepare the migration of your Android-based Microsoft Teams devices to AOSP (Android Open Source Project). The firmware has just

Read More
Facilitator, new AI agent for taking notes in meetings

Facilitator, new AI agent for taking notes in meetings

Introduction Microsoft recently announced a new feature for Teams Rooms: Facilitator ; an AI agent that takes notes during Teams meetings. This feature is currently in pre-public release

Read More
Impact analysis of Entra conditional access policies

Impact analysis of Entra conditional access policies

Introduction Conditional access in Entra is a security policy that allows administrators to control access to applications and resources based on specific conditions. These conditions can i

Read More
Enterprise Connect 2025 : Yealink SkySound CM50 Dante kit

Enterprise Connect 2025 : Yealink SkySound CM50 Dante kit

Introduction Enterprise Connect is an annual conference that brings together communications technology professionals, innovators, and others. This event showcases technological advances i

Read More
Enterprise Connect 2025 : New equipment for MTR

Enterprise Connect 2025 : New equipment for MTR

Introduction At the Microsoft Teams Enterprise Connect 2025 event, several new products were announced, offering innovative solutions to improve collaboration and communication in the workp

Read More
How to create a Windows local admin account via Intune LAPS

How to create a Windows local admin account via Intune LAPS

Introduction I wrote an article last February on how to replace the password of your MTR's local account using LAPS (Local Administrator Password Solution) in Intune. I concluded my article

Read More
How to enable Zoom and Webex meetings on MTR

How to enable Zoom and Webex meetings on MTR

Introduction In the modern business world, effective collaboration is essential. Organizations use various video conferencing platforms to stay connected, and it's crucial to be able to joi

Read More
New security approach for non-compliant emails

New security approach for non-compliant emails

Introduction Microsoft has announced a major update to Defender for Office 365 that strengthens email security by improving the handling of non-RFC compliant emails. This initiative is

Read More