Join our Newsletter — 33% off our NHI Course

LAPS

LAPS is a local administrator password management approach that assigns unique, rotating credentials for privileged local accounts. It reduces the risk of credential reuse across endpoints and limits the impact of compromise on one system. The core control objective is to prevent shared or static local admin passwords from becoming a lateral movement path.

What LAPS Does in Practice

LAPS is a local administrator password management control, not just a password rotation feature. Its purpose is to ensure each endpoint has a unique local admin secret so compromise on one machine does not automatically expose the same credential elsewhere.

That makes LAPS especially valuable where local administrator accounts still exist for support, recovery, or legacy software. It reduces shared-secret exposure and breaks one of the easiest paths for lateral movement after an endpoint is breached.

Why LAPS Matters for Endpoint Security

The main security value is containment. If attackers recover a local admin password from one host, they should not be able to reuse it on the rest of the fleet when LAPS is working correctly. This is why LAPS is often discussed alongside hardening programs for Windows estates and privileged access control.

LAPS also improves the security posture of environments where the local administrator account cannot be removed entirely. Rather than relying on one static password across many devices, the control turns that account into a per-device credential with a limited blast radius.

When used well, LAPS complements broader password hygiene, privileged access governance, and endpoint hardening measures. It does not replace privileged account management for central identities, but it closes a common gap at the device level.

How LAPS Reduces Lateral Movement Risk

LAPS addresses a familiar attacker pattern: obtain credentials from one endpoint, then reuse them to move laterally. A reused local admin password is valuable because it can unlock multiple systems without triggering obvious authentication failures.

By assigning distinct passwords, LAPS removes the reuse condition that makes that technique efficient. It also shortens the useful life of any recovered secret, because the password changes on a schedule rather than staying valid until manually reset.

In practice, the control is most effective when paired with tight administrative boundaries and strong workstation hygiene. Microsoft-oriented hardening guidance for Active Directory and Entra ID hardening is relevant here because LAPS works best when endpoint administration is deliberately segmented instead of loosely shared.

Operational Characteristics and Common Misunderstandings

LAPS is sometimes mistaken for a full privileged access strategy. It is not. It manages one specific class of secret, the local administrator password, and its value depends on how consistently the control is deployed, monitored, and recovered when needed.

It also does not remove the need to know who can read or reset the managed password. If the retrieval path is too broad, the control can become another privileged secret distribution mechanism rather than a containment measure.

That is why LAPS should be treated as part of a broader password and local admin hygiene program. The supporting discipline in Password Security and Password Manager Guide aligns with the same core idea: reduce reuse, reduce exposure, and limit the impact of compromise.

Risk and Threat Considerations

LAPS meaningfully lowers risk only when it is consistently applied and properly protected. If local admin passwords are not rotated, are shared across systems, or can be retrieved too broadly, the environment still has a reusable credential path that attackers can exploit for lateral movement.

Failure mechanism: compromise of one endpoint leads to theft or reuse of a local admin password, which then enables access to other machines that share the same secret or trust assumptions.

Impact: attackers can expand from a single host compromise into broader endpoint control, increasing the chance of privilege escalation, persistence, and rapid spread across the environment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management LAPS governs lifecycle management of local admin credentials.
AC-6 — Least Privilege LAPS supports limiting the scope of local administrative access.
IA-2 — Identification and Authentication (Organizational Users) Endpoint admin access still depends on strong authentication around privileged use.
Recommendation — Use IA-5 to rotate, store, and control local admin passwords on a managed schedule. Apply AC-6 to reduce standing local admin exposure and restrict privileged use. Enforce IA-2 for privileged administrators who manage endpoints and retrieve secrets.
ISO/IEC 27001:2022 A.5.15 — Access control LAPS is an access-control measure for privileged local accounts.
Recommendation — Define access rules for who may retrieve, reset, and use managed local admin passwords.
CIS Controls v8 CIS-5 — Account Management LAPS is an account-management safeguard for local administrative identities.
Recommendation — Use CIS-5 to inventory, control, and rotate local administrator accounts across endpoints.