Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteWindows LAPS automatic account management is configured through an Intune Account protection policy, but it has a strict platform requirement: automatic account creation and configuration require Windows 11 version 24H2, build 10.0.26100 or later, or Windows Server 2025 or later. The workflow is Endpoint security > Account protection: create a Windows LAPS policy, select the password-backup directory, configure password behavior, enable automatic account management, choose the account target, assign the policy to a pilot device group, and verify the account, backup, and event log.
Do not confuse Windows LAPS support with automatic account-management support. Earlier supported Windows versions can manage and rotate a local administrator password, but they cannot use the automatic account-creation and automatic-account-configuration settings described in this guide.
This guide follows the practical Intune workflow used in the HTMD Windows LAPS walkthrough, while the current Microsoft support boundary, policy behavior, defaults, and security requirements come from Microsoft Learn.
What Windows LAPS automatic account management does
Windows Local Administrator Password Solution, or Windows LAPS, is built into supported Windows releases. It automatically manages the password of a local administrator account and backs that password up to Microsoft Entra ID or Windows Server Active Directory, depending on the configured design. Intune delivers the Windows LAPS policy through the Windows LAPS configuration service provider, or CSP.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Automatic account management goes beyond password rotation. When enabled, Windows LAPS can control the basic configuration of the managed local account. For a custom account, it can:
- Create the account when the policy requires it.
- Remove or correct the account as required by policy.
- Add the account to the local Administrators group.
- Clear password-not-required and password-never-expires settings.
- Change the account description to indicate that Windows LAPS controls the account.
- Reject and log unexpected attempts to modify or delete the policy-controlled account.
The feature is designed to reduce the exposure created by shared or static local-administrator passwords. It is not a replacement for privileged-access governance, endpoint hardening, administrative tiering, event monitoring, or a documented recovery process.
Important support boundary: Windows 11 24H2 or later
Automatic account management requires Windows 11 version 24H2, build 10.0.26100 or later, or Windows Server 2025 or later.
Windows LAPS itself has a broader support range. Microsoft documents Windows 11 version 23H2 and later, supported Windows 10 releases that received the April 11, 2023 update or later, and supported Windows Server releases with the applicable updates. However, that broader Windows LAPS support does not include the automatic account-creation and automatic-account-configuration features.
In practical terms:
- Windows 11 24H2 or later: automatic account management is available when the other prerequisites are satisfied.
- Windows Server 2025 or later: automatic account management is available.
- Earlier supported Windows LAPS platforms: password management and rotation may be available, but use manual account management. A custom account must already exist.
- Unsupported or unpatched platforms: do not expect the Intune policy to create or configure the account.
Check the operating-system edition, version, and build on pilot devices before assigning this policy broadly. Support details can change, so use the current Windows LAPS overview and support documentation as the final authority.
Automatic versus manual account management
Manual account management is the default. In manual mode, Windows LAPS manages the password of an account selected by policy, but it does not create a custom account. If the selected custom account does not already exist, an administrator must create it separately through the Accounts CSP, an Intune-delivered script, or the operating-system image.
Automatic account management is optional. The controlling setting is AutomaticAccountManagementEnabled, whose default is false. The other automatic-account-management settings are ignored unless this setting is enabled.
| Area | Manual management | Automatic management |
|---|---|---|
| Default mode | Yes | No |
| Custom account creation | No; the account must already exist | Yes; Windows LAPS can create and manage it |
| Account configuration | Managed outside LAPS | Windows LAPS controls required account properties |
| Password management | Windows LAPS manages and rotates the password | Windows LAPS manages and rotates the password |
| Best fit | Unusual account requirements or an existing account lifecycle | Most standard deployments |
Microsoft recommends preferring automatic account management unless an unusual account configuration requires manual control. Microsoft also recommends using automatic management with a custom account and leaving the built-in Administrator account unused and disabled. That is Microsoft guidance, not a universal technical requirement; organizations should account for their recovery procedures, application dependencies, and administrative model.
Prerequisites for an Intune Windows LAPS deployment
1. Licensing and tenant services
The Intune Windows LAPS scenario requires Microsoft Intune and Microsoft Entra ID. Microsoft documents Intune Plan 1 and Microsoft Entra ID Free as sufficient for the core capability. Additional licenses may be required for other endpoint-management or identity features used by an organization.
2. Device enrollment and join state
Devices must be enrolled in Intune. A device that is merely workplace joined is not supported for Intune LAPS. Microsoft Entra-joined and hybrid-joined devices can use Microsoft Entra backup when the required Microsoft Entra LAPS configuration is in place.
For Microsoft Entra backup, also confirm that the device is enabled in Microsoft Entra ID. A device that is disabled in the directory can prevent password backup and rotation operations from applying as expected.
3. Operating-system version
For this guide’s automatic-account-management scenario, use Windows 11 24H2 build 10.0.26100 or later, or Windows Server 2025 or later. Confirm the version with Settings > System > About or the winver command before testing.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- Passwordless World - A revolutionary new way to protect your account info. By being FIDO2 certified by the world’s largest ecosystem for standard-based, interoperable authentication, FIDO2 makes everyday log-in experience effortless and passwordless yet more secure than generic password style security. **Note: FIDO2 does NOT support Mac log-in.
- Online Account Protection - FIDO2 key is backward compatible with U2F protocol and works with the newest Chrome browser with operating systems such as: Windows, macOS, or Linux. U2F can be supported and protected on all websites that follow U2F protocols.
- Multi-factored Authentication - Built-in, advanced HOTP (One Time Password) technology that completes the unique multi-factored authentication process. Eliminate worry and help prevent losing your account info to theft, phishing, hacking, or other online scams. Note: Only Enterprise Users using Azure Active Directory can access Windows Hello log-in via Thetis FIDO2 Security Key.
- Compact And Durable - 360° design with rotating aluminum alloy cover that shields the USB connector when not in use. Tough and durable alloy protects FIDO2 key from daily wear-and-tear, accidental drops, and scratches.
- Portable Design - ultra-portable design allows you to take your FIDO key anywhere you need it.
4. Administrative permissions
The administrator creating and managing the policy needs sufficient Intune role-based access control permissions to create and access endpoint security policies. The built-in Endpoint Security Manager role includes relevant security-baseline permissions by default, but role assignments should still be reviewed against the organization’s least-privilege requirements.
Viewing a managed local-administrator password and manually rotating it are separate privileged operations. They require the documented managed-device, organization, and remote-task permissions. Do not assume that every Intune administrator role automatically includes the rotate-password action. Review the current Intune Windows LAPS permissions documentation.
5. A defined backup and retrieval design
Decide where the password will be backed up before creating the policy:
- Microsoft Entra ID: generally appropriate for cloud-managed and hybrid-managed endpoints, provided the relevant Microsoft Entra LAPS capability and directory permissions are configured.
- Active Directory: appropriate where the organization’s architecture requires domain-based backup and retrieval.
Intune supplies the device policy; it does not by itself replace the directory-side configuration and permission design. Limit password retrieval to administrators and operational roles that genuinely need the credential for recovery or support.
Configure the Windows LAPS policy in Intune
Microsoft Intune’s labels can change as the admin center evolves. The navigation below reflects the current Windows LAPS policy workflow; if a template or label differs in your tenant, use the policy’s Windows LAPS CSP settings and Microsoft’s current documentation rather than relying on an old screenshot.
Step 1: Open Account protection
- Sign in to the Microsoft Intune admin center.
- Go to Endpoint security > Account protection.
- Select the option to create a new policy.
- Choose the Windows platform and the Windows LAPS policy profile presented by your tenant.
- Give the policy a descriptive name, such as
Windows LAPS - Automatic Custom Account - Pilot.
Keep the first policy narrowly scoped to a pilot device group. Avoid assigning several overlapping LAPS policies while testing.
Step 2: Select the password-backup directory
Choose Microsoft Entra ID or Active Directory in the policy’s password-backup directory setting. Select Microsoft Entra ID for a cloud-managed endpoint design only after confirming the required Microsoft Entra LAPS configuration and directory permissions.
Do not treat successful policy delivery as proof that backup succeeded. Backup must be validated separately on a representative device and in the directory location used by the organization.
Step 3: Configure password behavior
Configure the password requirements according to the organization’s recovery and security standard. The Windows LAPS policy exposes settings for:
- Password age or rotation schedule.
- Password length or passphrase behavior.
- Password complexity.
- Post-authentication reset behavior.
There is no universally correct value for every organization. A shorter password age may reduce the useful life of a recovered credential but can increase operational activity. Post-authentication reset behavior should reflect how help-desk recovery, break-glass access, and emergency support are performed. Document the chosen values so that a later administrator understands why they were selected.
The current Windows LAPS policy definitions and defaults are listed in Microsoft’s Windows LAPS management policy settings reference.
Step 4: Enable automatic account management
Turn on Automatic account management. This corresponds to AutomaticAccountManagementEnabled.
Rank #3
- Windows Hello for Windows 10/11 - Only works with Windows Hello on Windows 10/11 PCs and laptops. Plug the USB fingerprint reader into your computer and sign in with one touch. Not compatible with Mac, macOS, Linux or Chrome OS.
- Plug-and-Play Fingerprint Login - No extra app is needed on most genuine Windows systems. Insert the USB fingerprint scanner, set up fingerprint sign-in through Windows Hello, and unlock your PC without typing long passwords every time.
- Fast 0.5s 360° Recognition - Capacitive fingerprint technology supports quick authentication in about 0.5 seconds. 360° touch recognition helps read your fingerprint from different angles for faster, smoother daily login.
- Compact Scanner for PC & Laptop + Multi-User Support - Small, lightweight USB design works well for desktops, laptops, office PCs and shared home computers without built-in fingerprint sensors. Supports multiple Windows accounts and up to 10 fingerprints per user account. Smart-ID security helps protect saved passwords and encrypted folders with fingerprint access.
- Important Notes — Please Read Before Purchase - Support for Win10/11 32/64 bit original system. Not fit for the streamlined version. The Lite version has trimmed the biometric component, the fingerprint login device will not be able to recognize the Hello fingerprint option.It merely supports Windows Hello, does not fit for encrypting USB drives/files, and can merely support Windows system.It is recommended to prioritize plugging into the USB 2.0 interface of the motherboard. USB 3.0 docking stations are prone to power supply/interference and unstable recognition.
If this switch remains disabled, the dependent choices below do not control the local account. This is one of the most common reasons an administrator sees a correctly assigned policy but no automatically created account.
Step 5: Select the account target
Choose whether Windows LAPS should manage the built-in Administrator account or create a new custom account.
| Target | What to expect | Operational consideration |
|---|---|---|
| Built-in Administrator account | Windows LAPS manages the existing built-in account. | Consider Microsoft’s recommendation to leave this account unused and disabled where the organization’s recovery design allows it. |
| New custom account | Windows LAPS can create and manage the account automatically on eligible systems. | Usually the cleaner design for separating the managed recovery account from the built-in Administrator account. |
The target setting is represented by AutomaticAccountManagementTarget. Its default is the custom-account target. If you choose a custom account, automatic mode is what allows Windows LAPS to create it; this is different from manual mode, where a script or other provisioning method must create the account first.
Step 6: Set the account name or prefix
For a custom account, provide the desired account name or name prefix. If no value is supplied, Microsoft documents WLapsAdmin as the default name or prefix. This setting corresponds to AutomaticAccountManagementNameOrPrefix.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11If name randomization is enabled, Windows LAPS appends a random six-digit suffix whenever the password is rotated. Local Windows account names are limited to 20 characters, so Windows may truncate the configured prefix to leave room for the suffix. For example, a configured prefix could result in a current account name conceptually similar to WLapsAdmin123456; the exact generated name changes according to the policy behavior.
Because the account name can change, support staff should retrieve the current managed account identity from the approved administrative workflow rather than assuming that the original prefix is always the complete account name.
Step 7: Choose whether the account is enabled
Set the account enablement option according to the recovery design. The corresponding setting, AutomaticAccountManagementEnableAccount, defaults to false.
A disabled account may be desirable when the organization enables it only during an approved recovery operation. An enabled account may be necessary for a workflow that requires immediate local recovery access. Whichever option is selected, document who can retrieve the password, who can use the account, and how the account is disabled or rotated after use.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Step 8: Decide whether to randomize the account name
Optionally enable account-name randomization. The corresponding setting, AutomaticAccountManagementRandomizeName, defaults to false. When enabled for the applicable custom-account scenario, Windows LAPS adds a random six-digit suffix during password rotation and observes the 20-character local-account name limit.
Name randomization can make a predictable account name less useful to an attacker, but it also affects help-desk procedures, allowlists, monitoring queries, and scripts that refer to a local account by name. Test those dependencies before enabling it across the organization.
Step 9: Review and assign the policy
- Review the backup directory, password settings, automatic-management switch, account target, name or prefix, enabled state, and randomization choice.
- Assign the policy to a small pilot device group.
- Allow the device to check in and process the policy.
- Review the Intune per-device policy status before expanding the assignment.
- Resolve any conflict with another Windows LAPS policy before adding more devices.
Only one local account can be managed per Intune LAPS policy and device scenario. If two policies specify different target accounts, consolidate or correct the assignments before troubleshooting the account itself.
Validate the deployment on a pilot device
Validation should prove more than policy assignment. Use a representative device and complete every check below.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
- Certified to Microsoft’s highest fingerprint security standards (ESS & SDCP) for robust, hardware-isolated authentication. Supports next-gen Windows features, including Copilot Recall and Windows Hello with ESS support.
- Windows Hello ready for fast, password free fingerprint login to Windows and Microsoft 365 accounts
- On device fingerprint storage keeps biometric data securely within the key. Supports privacy regulations (GDPR, BIPA, CCPA) through on device biometric processing; TAA compliant.
- Reliable wired USB fingerprint authentication with USB C and USB A compatibility for desktop PCs.
- Consistent, all condition 360° fingerprint recognition.
- Confirm the platform: verify Windows 11 24H2 build 10.0.26100 or later, or Windows Server 2025 or later.
- Confirm enrollment and join state: verify that the device is enrolled in Intune and is not merely workplace joined.
- Confirm the Entra device state: for Microsoft Entra backup, verify that the device object is enabled.
- Confirm policy processing: review the device’s Intune policy status and verify that the Windows LAPS policy has applied successfully.
- Confirm the account: in Computer Management or another approved local-account management tool, verify that the intended account exists, has the expected enabled or disabled state, and belongs to the local Administrators group.
- Confirm account naming: if randomization is enabled, verify the current name and update support procedures that depend on it.
- Confirm backup: use an administrator with the documented permissions to verify that the password is present in the selected Microsoft Entra ID or Active Directory location.
- Confirm retrieval and rotation: test the Intune password-view and manual-rotation actions with an appropriately delegated account. Verify that the password changes and that the next password age or rotation state is reflected as expected.
- Review event logging: open Event Viewer and inspect Applications and Services Logs > Microsoft > Windows > LAPS > Operational. Look for policy processing, account-management, password-backup, and blocked-tampering events.
Perform the retrieval and rotation test with a controlled pilot account. Do not copy a production local-administrator password into tickets, spreadsheets, chat messages, or scripts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting common failures
| Symptom | Likely cause | What to check |
|---|---|---|
| The policy applies, but no custom account is created. | The device is below the automatic-management support boundary, or automatic management is disabled. | Confirm Windows 11 24H2/build 10.0.26100 or later or Windows Server 2025 or later. Then confirm AutomaticAccountManagementEnabled is enabled. |
| The custom account is missing on an older supported Windows LAPS device. | The device is using manual account management. | Create the account separately before Windows LAPS manages its password, or move the device to a supported automatic-management platform. |
| The account exists but has the wrong name or state. | The target, name or prefix, enablement, or randomization setting is different from the intended design. | Review the policy settings and the effective policy on the device. Remember that the dependent settings do nothing while automatic management is disabled. |
| Password backup does not appear in Microsoft Entra ID. | The Entra LAPS capability or directory permissions are incomplete, the device is disabled, or the device has not successfully processed the policy. | Check join state, Intune enrollment, the enabled state of the device object, directory configuration, policy status, and the Windows LAPS Operational event log. |
| An administrator cannot view or rotate the password. | The account lacks one or more documented Intune RBAC permissions. | Review managed-device, organization, and remote-task permissions. Do not assume that a broad Intune administrator role includes manual password rotation. |
| The account keeps changing or local changes are rejected. | A script, Accounts CSP policy, security tool, or administrator is attempting to modify an account controlled by Windows LAPS. | Remove the competing configuration and review the LAPS event log for blocked-tampering entries. Do not layer a separate local-user policy over an automatically managed account. |
| Several policies appear to manage different accounts. | Conflicting assignments specify different target accounts. | Use one clearly scoped policy and remove overlapping or contradictory assignments. |
| Support staff cannot find the account after rotation. | Account-name randomization is enabled and procedures still use the old prefix or name. | Retrieve the current account identity through the approved administrative workflow and update monitoring or recovery documentation. |
Do not combine automatic management with competing local-account policies
Once Windows LAPS automatically manages an account, avoid deploying a separate local-user policy or script that changes that same account’s name, membership, enabled state, password properties, or description. Windows LAPS may correct the change, reject it, or record it as a tampering event. Competing policies also make it difficult to determine whether a failure came from Intune, Windows LAPS, a script, or a security product.
If the organization needs a separately provisioned account, use manual account management and create that account through an intentional, documented provisioning process. If the organization wants Windows LAPS to own the account lifecycle, use automatic account management and remove other configuration mechanisms for that account.
Security and operational recommendations
- Use a unique managed password: do not share one local-administrator password across devices.
- Restrict retrieval: grant password-view and rotation permissions only to approved recovery and support roles.
- Protect the directory: treat Microsoft Entra ID or Active Directory backup permissions as privileged access.
- Test the recovery path: confirm that an authorized operator can retrieve the current account and password when a device is offline from normal management or requires local recovery.
- Consider a custom account: Microsoft recommends automatic management with a custom account and leaving the built-in Administrator account unused and disabled where practical.
- Monitor the LAPS event channel: investigate backup failures, policy-processing errors, unexpected account changes, and blocked-tampering events.
- Plan for random names: update help-desk, monitoring, EDR, and automation workflows if account-name randomization is enabled.
- Keep the wider control set: Windows LAPS does not replace endpoint hardening, privileged-access management, administrative tiering, or incident response.
A user who gains effective local-administrator control may still be able to interfere with local security mechanisms. LAPS limits credential reuse and reduces the lifetime of a recovered password, but it is one endpoint-security control rather than a complete privileged-access strategy.
Recommended Free Tools
When outside help makes sense
Organizations deploying LAPS across multiple operating-system versions, join states, directory environments, and administrative roles may benefit from Intune LAPS deployment help. If using an external provider, look for a provider that can demonstrate relevant Microsoft authorization or expertise, define exactly which Intune and Microsoft Entra work it will perform, state its geographic coverage and commercial terms, and include pilot testing, RBAC review, validation, and handover documentation in the scope.
Frequently Asked Questions
Can Windows LAPS automatic account management work on Windows 10?
Not in the automatic-account-management scenario covered here. Windows LAPS may be available on supported, updated Windows 10 releases for password management, but automatic account creation and configuration require Windows 11 24H2 build 10.0.26100 or later or Windows Server 2025 or later.
Does Intune create a custom local account automatically?
Yes, when automatic account management is enabled on an eligible Windows release and the custom-account target is selected. In manual mode, a custom account must already exist; it can be created through the Accounts CSP, an Intune script, or the operating-system image.
Why is the LAPS account not being created even though the Intune policy is assigned?
Check the Windows version first, then confirm that AutomaticAccountManagementEnabled is enabled. Also verify Intune enrollment, Microsoft Entra join state, device enablement in Microsoft Entra ID, policy conflicts, and the Windows LAPS Operational event log.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCan multiple local accounts be managed by one Intune LAPS policy?
No. Only one local account can be managed per Intune LAPS policy and device scenario. Conflicting policies that target different accounts must be resolved.
Does every Intune administrator have permission to view or rotate the LAPS password?
No. Viewing and manually rotating the password require the documented managed-device, organization, and remote-task permissions. Review the current Intune Windows LAPS RBAC documentation and use least-privilege role assignments.
The Bottom Line
For an eligible Windows 11 24H2 or Windows Server 2025 device, configure Windows LAPS in Endpoint security > Account protection, select the correct backup directory, enable automatic account management, choose the built-in or custom target, define the account state and naming behavior, and deploy first to a pilot device group. Then verify policy processing, account membership and state, directory backup, password retrieval, manual rotation, and LAPS event logging. The most important deployment rules are to respect the 24H2/Server 2025 support boundary, resolve conflicting policies, protect retrieval permissions, and avoid scripts or local-account policies that compete with Windows LAPS.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

