All lessons Leer en español

Security in depth · Unit 22 · Lesson 37 of 44

Local administrator passwords need ownership

Separate a successful managed-password rotation from retrieval rights and local administrator membership.

3 minreadyShort lesson

Helpful before thisWindows privilege escalation

See all lessons in this topic

After this lesson you can

  • Identify which LAPS-related controls a successful backup record does and does not verify.

Manage the password and its readers

Windows LAPS manages a local administrator account’s password on supported configurations, with backup to the configured directory service. Device join state and policy determine the supported backup option. A managed password helps avoid uncontrolled reuse, but it is still a powerful credential with readers who need justification.

Password retrieval authority is permission to obtain that credential from its backup location. It is distinct from local administrator membership and from the policy controlling password rotation. Success in one area is not evidence that the others meet the organization’s requirements.

A fictional device review

For device Cedar-12, the owner supplies:

  • Rotation and backup: current and successful for the managed account.
  • Approved password readers: Tier2Recovery only.
  • Effective retrieval permission: AllSupport, a broader group.
  • Local administrators: the required managed account plus a vendor account whose temporary approval has expired.

Assume the directory access review and group inventory are current. The packet contains no evidence of password retrieval or vendor activity. It supports two excess-authority findings, not an allegation that either was used.

Managed password → Restricted retrieval → Audited useManaged passwordRestricted retrievalAudited use
Managed rotation, restricted retrieval, and reviewed use are complementary controls; verify administrator membership separately.

Keep the acceptance rows separate

The directory owner should review the retrieval grant, while the device owner reviews the expired administrator membership. Preserve an approved recovery route so an unavailable normal sign-in service does not make the device unrecoverable. Record who can use that route and under what circumstances.

Acceptance needs current rotation/backup evidence, successful authorized recovery access, denied unapproved retrieval, and the intended administrator membership. Do not infer that LAPS manages every local account or that a credential-management feature automatically reduces all privileged workflows on the device.

Terms you met

Password retrieval authority

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. LAPS rotation and backup succeed, but the retrieval group is broader than approved and a temporary administrator remains. Which conclusion follows?

    Show the answer

    Correct answer: Password lifecycle evidence is positive, while retrieval scope and local membership still need correction. These are separate controls; a rotation record does not approve all credential readers or administrators.

Try it

  • WriteWrite a three-row acceptance card for rotation/backup, approved retrieval, and administrator membership. Assign an owner and the missing verification to each unresolved row.
References