Migrate LAPS from GPO to Intune

Yared H. Kebede 0 Reputation points
2025-08-18T19:29:21.3866667+00:00

I have LAPS configured using Group Policy, and it's working fine. Now, I would like to migrate the management to Intune. I followed an article I found online and set up our configuration accordingly, but I can't see the local administrator password in the Intune portal (it's not working).

What did I miss, or what should I do to successfully migrate LAPS from GPO to Intune?

1.I have enabled Azure AD LAPS within my Azure Tenant: Entra ID > Devices > Device Settings > Enable Microsoft Entra Local Administrator Password Solution (LAPS)

  1. I have enabled the Built-in Administrator Account: Devices > Configuration profiles > Create profile....Local Policies Security Options (Enabled).

3.Configured the LAPS Policy: In the Intune admin center, Endpoint security > Account protection > Create policy.

  1. Prerequisite: Windows platform: Windows 11 23H2
Microsoft Security | Intune | Configuration
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal 11,171 Reputation points
    2025-08-18T21:14:42.69+00:00

    Is the GPO also applied together with Intune policy? If yes, then GPO will take precedence.

    0 comments No comments

  2. Yared H. Kebede 0 Reputation points
    2025-08-19T05:01:03.2566667+00:00

    Yes, both the GPO and Intune policies are applied together. I excluded my test workstations from GPO-2, do I also need to exclude them from GPO-1?

    GPO-1:

    Computer Configuration > Policies >Policies > Security Settings> Local Policies/Security Options

    Accounts: Administrator account status : Enabled

    Accounts: Rename administrator account : "CSAdmin"

    GPO-2:

    Computer Configuration > Policies > Administrative Templates > LAPS > Policy

    Do not allow password expiration time longer than required by policy Enabled

    Enable local admin password management Enabled

    Password Settings Enabled

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.