Microsoft LAPS deployment tutorial

  1. Download the MSI file from here.
  2. Set a file share on your DC or file server. Set the share with Read permissions to Everyone (or use a dedicated group).
  3. On the hosted server, change the NTFS permissions as well, allowing Everyone (or the desired group) with Read only permissions.
  4. Login to one of your DCs. Add you user to the Schema Admin group.
  5. Install the downloaded MSI on your DC, include all options:
Import-Module AdmPwd.PSUpdate-AdmPwdADSchema
Set-AdmPwdComputerSelfPermission -OrgUnit <name of the OU to delegate permissions or full CN path>
Set-AdmPwdReadPasswordPermission -OrgUnit <name of the OU to delegate permissions> -AllowedPrincipals <users or groups>
find-admpwdextendedrights -identity "Comps"
  1. You’ll need to wait till the next cycle of the GPO to kick in before the password will actually change.
  2. Deciphering the password can be done via:
Import-Module AdmPwd.PSGet-AdmPwdPassword -ComputerName “name”
  • Computer Configuration > Administrative Templates > System > Logon > Always wait for the network at computer startup and logon = Enable
  • Computer Configuration > Administrative Templates > System > Group Policy > Specify startup policy processing wait time = 90 (or any other number you find suitable)




Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

DHCP Snooping Attack

REST API: Security through obscurity

eKYC vs Covid-19, time to relax ?


New Security Advisor Onboard!

CoinTiger Pool Adds VLK

Social Engineering: A Passion

{UPDATE} Dulce bien toca Hack Free Resources Generator

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Nadav Svirsky

Nadav Svirsky

More from Medium

Blog 5 — L’approvisionnement et fidelite de Dieu

Various Benefits I get When I Write My Essays Online

Game On: Datacentre Revolution in Nigeria

A rivalry to remember…