Track Windows LAPS Event log

Mighani 5 Reputation points
2023-12-22T09:43:33.6+00:00

Hi

I want to know how can I track security logs in active directory after a helpdesk click on "show password" or after click on "expire now" on a computer account.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,491 Reputation points Moderator
    2023-12-22T11:19:50.4966667+00:00

    Hi @Mighani

    Unfortunately It's not passible to track who read the password

    All LAPS event tracked under Applications and Services > Logs > Microsoft > Windows > LAPS > Operational.

    I invite you to read this article for more details:

    Password update confirmation events


    Please don't forget to accept helpful answer


  2. Soleh Haidar 0 Reputation points
    2025-07-24T07:53:36.4+00:00

    I know this is an old thread, but I just wanted to try and help.

    I actually found a way to get a report on who has read the LAPS password. Here's my current environment setup:

    Using Entra ID to manage LAPS

    Devices enrolled in Intune

    Endpoint Analytics enabled

    Azure AD logs sent to Azure Workbooks

    Using a KQL query, you can search for "Recover device local administrator password".

    You’ll be able to see in detail who accessed the LAPS password and on which PC.image

    User's image

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.