Anonymous
My feedback
-
482 votes
This is currently in planning for enabling it for Azure AD joined devices, NOT for AAD DS
An error occurred while saving the comment Anonymous supported this idea ·
Our devices in Microsoft Security Center show as unsecure because of this not being configured even in Azure AD joined devices - it checks for a registry key that only works with LAPS. Would be nice if LAPS was configured so that we wouldn't have to ignore this setting on several hundred intune devices
Remediation options
Option 1 - Set the following Group Policy:
Computer Configuration\Policies\Administrative Templates\LAPS\Enable Local Admin Password Management
To the following value: Enable
Option 2 - Set the following registry value:
HKLM\SOFTWARE\Policies\Microsoft Services\AdmPwd\AdmPwdEnabled
To the following REG_DWORD value: 1
https://securitycenter.windows.com/security-recommendations/sca-_-scid-84?search=scid-84