Site icon WinCert

How to install and configure LAPS (Local Administrator Password Solution)

cryptolocker, virus, malware

Businesswoman holding tablet pc entering password. Security concept

<p>Local Administrator Password Solution &lpar;<b>LAPS<&sol;b>&rpar; is a <b>Microsoft<&sol;b> product for managing local administrator passwords&period; Using LAPS passwords are stored in Active Directory &lpar;AD&rpar; and can be controlled via Group Policy&period;<&sol;p>&NewLine;<h4><strong>Installation<&sol;strong><&sol;h4>&NewLine;<p>For a start&comma; LAPS has to be downloaded from <a href&equals;"https&colon;&sol;&sol;www&period;microsoft&period;com&sol;en-us&sol;download&sol;details&period;aspx&quest;id&equals;46899&amp&semi;Search&equals;true" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">HERE<&sol;a>&period; The download package contains both <strong>x86 and x64<&sol;strong> versions of <strong>LAPS<&sol;strong> along with the datasheet&comma; operations guide&comma; and technical specification&period; It&&num;8217&semi;s worth saying that LAPS <strong>does not require a dedicated server<&sol;strong> as generated passwords are stored in Active Directory&period;<&sol;p>&NewLine;<p>The following components have to be installed on the machine from which LAPS will be configured&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3318" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;09&sol;laps-installation-1-1&period;png" alt&equals;"" width&equals;"488" height&equals;"383" &sol;><&sol;p>&NewLine;<p><strong>AdmPwd GPO Extension<&sol;strong> &&num;8211&semi; This component is NOT required if this machine won&&num;8217&semi;t be LAPS managed&period;<br &sol;>&NewLine;<strong>Fat client UI<&sol;strong> &&num;8211&semi; This will install fat client UI and related files&period; This is needed for viewing the LAPS configured passwords&period;<br &sol;>&NewLine;<strong>PowerShell module<&sol;strong> &&num;8211&semi; This will install <strong>ADMPwd&period;PS<&sol;strong> module which is required for configuring permissions&comma;  Active Directory Schema Extension and command-line management&period;<br &sol;>&NewLine;<strong>GPO Editor Templates<&sol;strong> &&num;8211&semi; This will install <strong>ADMX templates<&sol;strong> that will be used to configure and deploy LAPS using Group Policy&period;<&sol;p>&NewLine;<h4>Configuration<&sol;h4>&NewLine;<p>Once <strong>LAPS<&sol;strong> is installed we have to <strong>run Powershell in elevated mode<&sol;strong> using an account that is a member of the <strong>Schema Admins<&sol;strong> Active Directory group&period;<&sol;p>&NewLine;<p>Enter the following command in Powershell to import <strong>ADMPwd&period;PS<&sol;strong> module that we have installed before&period;<br &sol;>&NewLine;<strong>Import-Module AdmPwd&period;PS<br &sol;>&NewLine;<&sol;strong><&sol;p>&NewLine;<p>In the next step&comma; we&&num;8217&semi;ll be extending the AD Schema&period;<br &sol;>&NewLine;<strong>Update-AdmPwdADSchema<&sol;strong><&sol;p>&NewLine;<p>With this done&comma; we&&num;8217&semi;ll have two new attributes visible on the properties of the computer objects in Active Directory&period;<&sol;p>&NewLine;<p><strong>ms-MCS-AdmPwd<&sol;strong><br &sol;>&NewLine;<strong>ms-Mcs-AdmPwdExpirationTime<&sol;strong><&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3319" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;09&sol;laps-password-2&period;jpg" alt&equals;"" width&equals;"237" height&equals;"39" &sol;><&sol;p>&NewLine;<p>One attribute is used for storing the administrative password&comma; while the other one holds password expiration time&period;<&sol;p>&NewLine;<p>Now we have to grant write permissions on both of these attributes for the SELF account&period;<&sol;p>&NewLine;<p>Enter the following command in elevated Powershell window&colon;<br &sol;>&NewLine;<strong>Set-AdmPwdComputerSelfPermission -Identity &OpenCurlyDoubleQuote;OU name”<&sol;strong><&sol;p>&NewLine;<p>Replace &&num;8220&semi;<strong>OU Name&&num;8221&semi;<&sol;strong> with the name of the Active Directory Organizational Unit that contains computers or servers&period; For test purposes&comma; you can do this only with one organizational unit&period; Later on&comma; this command can be applied for the top-level OU or individual computers and servers OUs&period;<br &sol;>&NewLine;<em><strong>Note&colon; If your domain holds multiple same OU names&comma; Distinguished Name should be used instead of  &&num;8220&semi;OU name&rpar;&period;<&sol;strong><&sol;em><&sol;p>&NewLine;<p>To grant permissions for a group or a user for the following OU the following command has to be used&colon;<br &sol;>&NewLine;<strong>Set-AdmPwdResetPasswordPermission –Identity &OpenCurlyDoubleQuote;OU name” -AllowedPrincipals &OpenCurlyDoubleQuote;AD group or username”<&sol;strong><&sol;p>&NewLine;<p>If for whatever reason above command won&&num;8217&semi;t work&comma; you can delegate control to AD group or individual user to a specified OU and add <strong>All extended rights<&sol;strong> permission for <strong>This object and all descendant objects<&sol;strong> as seen in the screenshot below&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-3326 size-full" title&equals;"How to install and configure LAPS" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;09&sol;laps&lowbar;extended&lowbar;rights&period;png" alt&equals;"How to install and configure LAPS" width&equals;"964" height&equals;"608" &sol;><&sol;p>&NewLine;<p>Current permission holders with Extended rights for a specific OU can be checked with the following command&colon;<br &sol;>&NewLine;<strong>Find-AdmPwdExtendedRights –Identity &OpenCurlyDoubleQuote;OU name”<&sol;strong><&sol;p>&NewLine;<p>The only thing that we should do now is to create a GPO and link it to a specified computer or server container&period;<&sol;p>&NewLine;<p>With this policy we can define if <strong>LAPS is enabled&comma; name of the local administrator account that we&&num;8217&semi;ll be used in LAPS policy&comma; password complexity&comma; password length&comma; and password age<&sol;strong>&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-3329 size-full" title&equals;"How to install and configure LAPS" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;09&sol;laps&lowbar;policy&period;png" alt&equals;"How to install and configure LAPS" width&equals;"1541" height&equals;"388" &sol;><&sol;p>&NewLine;<p>That should be it&period; Questions and suggestions are welcome&excl;<&sol;p>&NewLine;

Exit mobile version