Azure Domain Services Support for LAPS
Allow (or automatically install) LAPS within Azure Domain Services since this is the Microsoft supported standard for local administrator accounts.
LAPS: https://technet.microsoft.com/en-us/library/security/3062591.aspx

This is currently in planning for enabling it for Azure AD joined devices, NOT for AAD DS
62 comments
-
Andrew commented
This would be EXTREMELY useful
-
Brad commented
Only Azure AD, having Azure Active Directory Domain Services as a requirement would be too expensive it not currently using AADS. :)
When is the release date?
-
Brad commented
Only Azure AD, having Azure Active Directory Domain Services as a requirement would be too expensive it not currently using AADS. :)
-
SB commented
We definitely want this on AAD joined devices. But why not have both? ;)
-
James R commented
I’m looking for this for AAD joined machines. I would be happy to see this as an Intune feature or AAD. I’m currently reviewing our setup and looking if moving to AAD is right for us. LAPS is something that I need to consider.
-
Steve commented
Having it directly in AAD would be even better than having it in Azure Domain Services or InTune!
-
M Giles commented
incidentally have you guys seen the "SLAPS" solution?
https://www.srdn.io/2018/09/serverless-laps-powered-by-microsoft-intune-azure-functions-and-azure-key-vault/ -
M Giles commented
Primarily Azure Active Directory joined windows 10 machines.
-
Garrity, Thomas commented
Both.
-
Anonymous commented
Azure Active Directory joined windows 10 machines + 10 :-)
-
Mads Højlund commented
LAPS for Azure Active Directory joined windows 10 machines would be great!
-
Andre commented
This would be great!
-
Anonymous commented
This is fantastic news. Please release this ASAP! Very excited that this is now on the agenda :)
-
Anonymous commented
+1
-
John commented
Awesome news! Yes, I would like this feature for AAD joined Windows 10 machines. It would be great to manage it through Intune.
My scenario is the ability to change the local admin passwords. Currently, I'm using Intune OMA-URI to create a local admin account and set the password, BUT I cannot change the password once it has been set (using this method).
I find the need to change the local admin passwords is necessary. I have 2 frequent scenarios for this need: 1) good security practice and 2) IT admin turnover.
-
Anonymous commented
<bump>
-
Dhirendra commented
Is there new development on this? or MS scrapped this beautiful idea? any other solution from MS for LAPS on AAD
-
Bryan commented
I concur as well, and I there are two scenarios I'd like to see: First, for machines in AAD Domain Services. Second, for AAD-joined Windows clients. In both cases, I'd like an easy way to expose this, much like in Windows Admin Center. As Mateusz pointed out, it would be great to have this as something that could be integrated in third-party solutions (TeamViewer, for example).
-
M Giles commented
I would consider this essential.
-
Alex commented
Agree