Share via

LAPS Restrict Domain Controller

TAN HAN LIM 136 Reputation points
2023-05-09T14:01:59.51+00:00

Hi,

My environment configured with LAPS and usually it query laps password from few domain controllers.

Could it possible to restrict 1 or 2 dedicated domain controllers to respond towards laps password queries from client?

Is there any registry in client to control that? or any DC query priority in laps?

Thanks mate.

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments

Answer accepted by question author

Limitless Technology 45,241 Reputation points
2023-05-10T10:32:45.6166667+00:00

Hello Tan Han Lim,

Thank you for your question and for reaching out with your question today.

When configuring LAPS you can deploy it to whichever DCs you would like it to be functional on. This would have been carried out in your environment at initial setup and if LAPS requests are accepted by multiple DCs, I would assume that LAPS was deployed to all of your DCs. In my experience, I would deploy LAPS to only my main DC as having it on multiple DCs can cause issues in an environment.

If the reply was helpful, please don’t forget to upvote or accept as answer.

Best regards.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.