Windows LAPS (Local Administrator Password Solution) rotates local admin passwords automatically, preventing lateral movement via shared local admin credentials.
Aanbeveling
IMPLEMENT
Risico zonder
Critical
Risk Score
9/10
Implementatie
6u (tech: 4u)
Van toepassing op:
β Windows β Intune
Standaard: same local admin password over alle devices. Attacker compromises one device β gebruikt local admin password voor lateral movement to alle devices. LAPS: unique password per device, automatische rotation, centrally managed.
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Schakel in Windows LAPS via Intune. elke device gets unique local admin password, rotated elke 30-90 days, backed up to Azure AD, retrievable door geautoriseerde admins only.
Intune β Devices β Configuration profiles β Windows LAPS
Schakel in LAPS voor Azure AD
Password rotation: 30 days
wachtwoordcomplexiteit: 14+ characters
Backup to Azure AD
Implementeer to alle Windows devices
Admins retrieve passwords via Azure AD device properties
Vereisten
Windows 10/11
Azure AD joined
Intune subscription
Windows 11 22H2+ (native LAPS) of LAPS client
Implementatie
Intune β Devices β Configuration profiles β Windows LAPS
Schakel in LAPS voor Azure AD
Password rotation: 30 days
wachtwoordcomplexiteit: 14+ characters
Backup to Azure AD
Implementeer to alle Windows devices
Admins retrieve passwords via Azure AD device properties
Compliance en Auditing
CIS Intune
BIO 09.04
ISO 27001 A.9.4.3
NIS2 Artikel 21
Monitoring
Gebruik PowerShell-script laps-enabled-azuread.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script laps-enabled-azuread.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
BIO: 09.04 - Local admin management
ISO 27001:2022: A.9.4.3 - Privileged access
NIS2: Artikel - credential management
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).