LAPS implementation on built-in administrator account

raja waseem 51 Reputation points
2022-10-12T11:06:40.823+00:00

How to implement LAPS in the following conditions:

Thousands of client computers with custom local admins created (different names), So through GPO we can remove the administrators group membership & Configure the LAPS on
Builtin 'Administrator' account but, by default, it is disabled in Windows 10 computers & Unable to enable as it requires Password & we can't apply a password through GPO.
Also, we can't create an admin user through GPO.

Manually it's not possible for thousand of computers.

any help in these conditions?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,746 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,124 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,852 questions
0 comments No comments
{count} vote

3 answers

Sort by: Most helpful
  1. Limitless Technology 43,931 Reputation points
    2022-10-13T09:15:47.823+00:00

    Hello

    Thank you for your question and reaching out.

    In your scenario you can create Custom Local Admin for all your Clients PC using LAPS GPO.

    1. In LAPS GPO settings -> “Name of administrator account to manage” Type name like "LAPSAdmin"
    2. Open GPO --> Computer Configuration –> Preferences –> Control Panel Settings –> Local Users and Groups;

    -----------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    1 person found this answer helpful.
    0 comments No comments

  2. raja waseem 51 Reputation points
    2022-10-13T11:28:44.197+00:00
    1. unable to create through LAPS
    2. It's not possible as it needs to set a password because of the domain password policies

    Kindly explain.

    1 person found this answer helpful.
    0 comments No comments

  3. Gokhan Cil 1 Reputation point
    2022-12-23T00:33:20.607+00:00

    Just use Group policy preferences and remove all the false admin accounts than apply LAPS to all workstations through GPO. and install LAPS MSI to all clients with a deployment through GPO

    273458-image.png

    0 comments No comments