---
title: How to Deploy Windows LAPS with Entra ID Backup | Datatechs Consulting
description: "Step-by-step guide to deploying Windows LAPS with Entra ID backup: the tenant switch, Intune policy settings, permissions, verification and fleet auditing."
image: https://www.datatechs.co.uk/hubfs/Blog%20Images/datatechs-blog-windows-laps-cover.png
---

[Skip to content](https://www.datatechs.co.uk/blog/how-to-deploy-windows-laps-with-entra-id-backup#main-content)

[![Datatechs home](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited.png?width=2130&height=676&name=Datatech%20Consulting%20Limited.png "Datatechs home")](https://www.datatechs.co.uk) 

[![](https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/)

[Home](https://www.datatechs.co.uk/)

[Services](https://www.datatechs.co.uk/services)

[M365 Security Audit](https://www.datatechs.co.uk/audit) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance) [Power Platform](https://www.datatechs.co.uk/services/power-platform) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure)

[View all services →](https://www.datatechs.co.uk/services)

[Security Audit](https://www.datatechs.co.uk/audit)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials)

[View the full audit →](https://www.datatechs.co.uk/audit)

[MSP Partners](https://www.datatechs.co.uk/msp-partners)

Resources

Free Downloads

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials)

[About](https://www.datatechs.co.uk/about) [Blog](https://www.datatechs.co.uk/blog) 

[Contact Us](https://www.datatechs.co.uk/contact)

[Home](https://www.datatechs.co.uk/) [Services](https://www.datatechs.co.uk/services)

[M365 Security Audit](https://www.datatechs.co.uk/audit) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance) [Power Platform](https://www.datatechs.co.uk/services/power-platform) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure) 

[Security Audit](https://www.datatechs.co.uk/audit)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials) 

[MSP Partners](https://www.datatechs.co.uk/msp-partners) Resources

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials) 

[About](https://www.datatechs.co.uk/about) [Blog](https://www.datatechs.co.uk/blog) [Contact Us](https://www.datatechs.co.uk/contact)

[← Back to blog](https://www.datatechs.co.uk/blog)

Microsoft 365 Security · Identity and Access

# How to Deploy Windows LAPS with Entra ID Backup

Marcus Harris · 18 September 2026

In this article

Windows LAPS puts a unique local administrator password on every device and backs it up to Entra ID. The tenant-level switch that allows that backup is off by default, which is how a policy reports as applied across ninety devices and leaves you with twelve stored passwords.

This covers the whole deployment: the tenant prerequisite, the Intune policy, assignment, who can read the passwords, how to confirm a rotation actually happened, and how to check coverage across a fleet. Allow about twenty minutes per tenant for setup and five for verification.

---

## Applies to

- Windows 10 21H2 and later, Windows 11, and Windows Server 2019 and later, with the April 2023 or later cumulative update installed.
- Devices that are Entra joined or Entra hybrid joined, and enrolled in Intune.
- A tenant with an Intune licence and Microsoft Entra ID.

Windows LAPS is built into the operating system. There is no MSI to deploy, no schema extension and no client side extension, unlike the legacy LAPS product of the same name. If legacy LAPS policy is still in scope on the same devices, remove it first: Windows LAPS detects a legacy policy and defers to it, so the Intune policy will appear to apply while nothing is written to Entra.

---

## How it works

![Four-stage diagram: an Intune account protection policy is delivered to a Windows device, the device sets a new local administrator password, the password is written to the device object in Entra ID with a backup timestamp, and an engineer with the password read permission retrieves it. A callout notes that the Entra tenant switch must be on for the password to be stored](https://www.datatechs.co.uk/hubfs/Blog%20Images/datatechs-diagram-laps-flow.png)

The tenant switch sits between the device and the directory, which is why a policy can report as applied while no password is stored.

The device does the work locally and writes the result to its own object in Entra ID. Retrieval is a separate, permissioned action. Both halves need configuring.

---

## Step 1: Enable LAPS on the Entra tenant

The tenant-level switch is off by default. Until it is on, devices will process the policy and fail to store the password.

**Where to find it**entra.microsoft.com › Identity › Devices › Overview › Device settings

Set **Enable Microsoft Entra Local Administrator Password Solution (LAPS)** to **Yes** and save. Add this to your tenant onboarding checklist: it is not visible from the Intune side, and no policy status will report it as missing.

---

## Step 2: Choose the managed local account

Windows LAPS manages one local account per device. There are two options.

| Option | Behaviour | Watch for |
| --- | --- | --- |
| **Built-in Administrator (RID 500)** | LAPS rotates the password of the existing account. | The account is disabled by default. LAPS will rotate a disabled account's password indefinitely and the credential will not sign in. Enable it, or use the option below. |
| **LAPS-managed account** | LAPS creates the account, adds it to the local Administrators group, keeps it enabled and rotates it. It is recreated if deleted or removed from the group. | Requires automatic account management to be enabled in the policy. Choose a name that is not "admin" and not your company name. |

Use the same option and the same account name in every tenant you manage. A recovery process that depends on recalling which customer uses which account name adds delay at the worst moment.

---

## Step 3: Create the Intune policy

**Where to find it**intune.microsoft.com › Endpoint security › Account protection › Create Policy › Windows › Local admin password solution (Windows LAPS)

| Setting | Value | Reason |
| --- | --- | --- |
| Backup Directory | Backup the password to Azure AD only | Determines where the password is stored and how it is retrieved. |
| Administrator Account Name | Your chosen account name | Leave blank to manage the built-in Administrator instead. |
| Automatic Account Management | Enabled | Creates and maintains the account named above. |
| Password Age Days | 30 | Routine rotation interval. |
| Password Length | 20 or more | The password is copied, not typed, so length costs nothing. |
| Password Complexity | Large letters, small letters, numbers and special characters | Full character set. |
| Post Authentication Actions | Reset the password and log off the managing account | Rotates the password after use rather than only on a schedule. |
| Post Authentication Reset Delay | 8 hours | Long enough for a work session, short enough that the credential does not outlast it. |

Password Age Days and Post Authentication Actions do different jobs, and only the second one limits the life of a password that has been retrieved and pasted into a ticket.

![Two timelines compared. With post-authentication actions configured, the password is retrieved, used, then automatically reset and the account signed out after the reset delay, and a new password is stored. Left at default, the password is retrieved and used but stays valid until the password age limit is reached, up to thirty days later](https://www.datatechs.co.uk/hubfs/Blog%20Images/datatechs-diagram-laps-post-auth-reset.png)

Both timelines start with the same retrieval. The difference is how long the credential is still worth something afterwards.

---

## Step 4: Assign the policy

Assign to a dynamic device group so newly enrolled devices are covered without manual work.

```
(device.deviceOSType -eq "Windows") and (device.deviceTrustType -eq "AzureAd")
```

Exclude device types with a different local account model, such as kiosk or shared devices, if you have them.

---

## Step 5: Grant permission to read the passwords

Reading a stored password is a privileged action and needs a directory role that carries the permission. Rather than assigning Cloud Device Administrator or Global Administrator broadly, create a custom directory role containing:

```
microsoft.directory/deviceLocalCredentials/password/read
```

On the Graph side there are two scopes, and they are not interchangeable. `DeviceLocalCredential.ReadBasic.All` returns device names and backup timestamps without passwords, and is all your reporting and auditing needs. `DeviceLocalCredential.Read.All` returns the password itself, and belongs only where recovery is the purpose.

**Where to read a password**intune.microsoft.com › Devices › All devices › (select a device) › Local admin password

Retrievals are recorded in the Entra audit log. If you work through GDAP, confirm the role you receive in the customer tenant carries the permission, as a relationship scoped to Helpdesk Administrator does not.

---

## Step 6: Verify on a pilot device

A compliant policy status is not confirmation that a password was stored. Verify on one device before rolling out further.

**1. Force a policy cycle and read the LAPS event log.** Run from an elevated PowerShell session on the device:

```
Invoke-LapsPolicyProcessing

Get-WinEvent -LogName 'Microsoft-Windows-LAPS/Operational' -MaxEvents 30 |
    Select-Object TimeCreated, Id, LevelDisplayName, Message |
    Format-List
```

Event ID 10018 confirms the password was successfully updated in Entra. Policy processing events with no 10018 means the password was generated but not stored.

**2. Retrieve the password from the directory.** Run from an administrative workstation:

```
Connect-MgGraph -TenantId '<tenant-id>' -Scopes 'DeviceLocalCredential.Read.All'

Get-LapsAADPassword -DeviceIds 'LT-0042' -IncludePasswords -AsPlainText
```

**3. Sign in to the device** with the account name and password returned.

**4. Rotate immediately afterwards**, so the credential you displayed is no longer valid:

```
Reset-LapsPassword
```

---

## Step 7: Audit coverage across your tenants

Once the deployment is proven on one device, the useful number is how many devices in each tenant hold a current password. Reading backup timestamps needs only the basic scope, so this is safe to run on a schedule.

```
$Tenants = Get-Content .\tenants.txt   # one tenant id per line

foreach ($TenantId in $Tenants) {

    Connect-MgGraph -TenantId $TenantId -NoWelcome `
        -Scopes 'DeviceLocalCredential.ReadBasic.All','Device.Read.All'

    $uri  = 'https://graph.microsoft.com/v1.0/directory/deviceLocalCredentials' +
            '?$select=deviceName,lastBackupDateTime'
    $rows = @()

    do {
        $page  = Invoke-MgGraphRequest -Method GET -Uri $uri
        $rows += $page.value
        $uri   = $page.'@odata.nextLink'
    } while ($uri)

    $stale = $rows | Where-Object {
        [datetime]$_.lastBackupDateTime -lt (Get-Date).AddDays(-45)
    }

    [pscustomobject]@{
        Tenant        = $TenantId
        DevicesBacked = $rows.Count
        Stale         = $stale.Count
    }
}
```

Compare `DevicesBacked` against the count of Windows devices in the tenant. A large gap points to one of the causes below.

---

## Troubleshooting

| Symptom | Cause | Fix |
| --- | --- | --- |
| Policy reports as applied, no passwords appear in Entra. | The tenant switch is off. | Step 1. Devices store the password on the next cycle. |
| No LAPS events at all on the device. | A legacy LAPS policy is still in scope and takes precedence. | Remove the legacy GPO and client side extension, then rerun `Invoke-LapsPolicyProcessing`. |
| Password retrieved, sign-in fails. | The managed account is disabled, usually the built-in Administrator. | Enable the account, or switch to a LAPS-managed account per step 2. |
| Error events referencing the managed account. | The account name in the policy does not exist and automatic account management is off. | Enable automatic account management, or correct the name. |
| Nothing stored on cloud-only devices. | Backup Directory is set to Active Directory. | Set it to Azure AD only. |
| Retrieved passwords stay valid for weeks. | Post Authentication Actions left unconfigured. | Set it to reset and log off, with a reset delay. |
| Password field is not visible in Intune. | The signed-in account lacks the password read permission. | Assign the role from step 5, and check the GDAP role if delegated. |

Once steps 1 to 6 are done in a tenant, the Graph script in step 7 is all that is needed to keep an eye on it.

Topics: [Microsoft 365 Security](https://www.datatechs.co.uk/blog/tag/microsoft-365-security) [Identity and Access](https://www.datatechs.co.uk/blog/tag/identity-and-access)

Share this article

[LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https://www.datatechs.co.uk/blog/how-to-deploy-windows-laps-with-entra-id-backup) [X (Twitter)](https://x.com/intent/post?url=https://www.datatechs.co.uk/blog/how-to-deploy-windows-laps-with-entra-id-backup&text=)

M

Marcus Harris

## Keep reading

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-tenant-sprawl.png?width=640&height=360&name=datatechs-blog-tenant-sprawl.png)](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

Microsoft 365 Security

### [Six Global Admins and Audit Logging Off: Inheriting a Three-Year-Old Tenant](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

28 August 2026 

[Read more →](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-gdap.png?width=640&height=360&name=datatechs-blog-gdap.png)](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants)

Identity and Access

### [Auditing Delegated Admin Access Across Client Tenants](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants)

4 September 2026 

[Read more →](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants)

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-ca-baseline.png?width=640&height=360&name=datatechs-blog-ca-baseline.png)](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

Microsoft 365 Security

### [Deploying a Conditional Access Baseline to Any Tenant](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

11 September 2026 

[Read more →](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

GET IN TOUCH

## Looking for help with your Microsoft 365 environment?

Our team works with small and mid-sized organisations to secure, audit, and manage their Microsoft 365 configuration. No jargon, no unnecessary overhead.

[Book a discovery call](https://www.datatechs.co.uk/book-a-call)[View our services →](https://www.datatechs.co.uk/services)

[![Datatechs](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png?height=56&name=Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/)

Microsoft 365 security and compliance for organisations and MSPs.

Services

- [M365 Security Audit](https://www.datatechs.co.uk/audit)
- [Professional Services](https://www.datatechs.co.uk/services/professional-services)
- [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk)
- [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance)
- [Power Platform](https://www.datatechs.co.uk/services/power-platform)
- [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure)

Resources

- [Blog](https://www.datatechs.co.uk/blog)
- [M365 Security Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials)

Company

- [About](https://www.datatechs.co.uk/about)
- [MSP Partners](https://www.datatechs.co.uk/msp-partners)
- [Contact](https://www.datatechs.co.uk/contact)
- [Book a call](https://www.datatechs.co.uk/book-a-call)

Contact

- [hello@datatechs.co.uk](mailto:hello@datatechs.co.uk)
- United Kingdom

© 2026 Datatechs Consulting Limited. Registered in England and Wales, company number 16868376. Registered office: Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG.

[Privacy Policy](https://www.datatechs.co.uk/privacy-policy) [Terms](https://www.datatechs.co.uk/terms)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Marcus Harris",
    "url" : "https://www.datatechs.co.uk/blog/author/marcus-harris"
  },
  "dateModified" : "2026-09-18T08:00:00.082Z",
  "datePublished" : "2026-09-18T08:00:00.000Z",
  "headline" : "How to Deploy Windows LAPS with Entra ID Backup",
  "image" : [ "https://www.datatechs.co.uk/hubfs/Blog%20Images/datatechs-blog-windows-laps-cover.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.datatechs.co.uk/blog/how-to-deploy-windows-laps-with-entra-id-backup",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited.png"
    }
  }
}
```