The search filter is invalid (Windows Laps)

create share 656 Reputation points


I have enabled Windows Laps in AD but when I try to run the below command

Set-LapsADComputerSelfPermission -Identity Test

I am getting "Set-LapsADComputerSelfPermission : The search filter is invalid."

Secondly, how to enable permissions for an OU having a space in it? For Example "Desktops HO"?


Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,216 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Phil Dormann 10 Reputation points

    For me it worked to use the distinquished name of the OU for example:
    Set-LapsADComputerSelfPermission -Identity "OU=Company,DC=exoip,DC=local"

    You can find this if you right click the OU you want to use LAPS for and click on properties. There you have to go on attribute editor. The first thing there should be the distinquished name. Maybe this helps you if not I dont know another solution.

    2 people found this answer helpful.
    0 comments No comments

  2. create share 656 Reputation points

    The problem was resolved after I applied the Group Policy on the main domain container instead of the OU. Not sure if this was the actual reason or something else because then it accepted the below command

    Set-LapsADComputerSelfPermission -Identity "OU=Desktops HO,DC=domain,DC=com"


    0 comments No comments