HomeBlogCybersecurity

Turn On Windows LAPS, Then Remove Local Admin Rights

Technician unplugging a red ethernet cable from a network switch, representing removing local admin rights and enabling Windows LAPS

Your staff shouldn't be local administrators on their work PCs. Turn on Windows LAPS so IT has one managed admin account per machine with a rotating password, then take everyone else's rights away. LAPS is built into Windows and costs nothing extra.

Most small offices skip this because it sounds like it'll create tickets. It creates a few. It also closes one of the easiest paths an attacker has.

Why are local admin rights a problem?

Local admin rights let whoever's signed in install software, switch off security tools and change system settings. Malware that runs in that session inherits the same power. That's the whole problem.

Here's the scale. Microsoft reported 1,360 vulnerabilities in 2024, a record, and elevation of privilege flaws made up 40% of them, 554 in total, according to BeyondTrust's 2025 Microsoft Vulnerabilities Report.

An elevation of privilege bug exists to turn a standard user into an admin. When your users already are admins, the attacker doesn't need one.

There's a second problem. Many offices set up every PC with the same local admin password years ago and never changed it. Steal that password from one laptop and you can sign in to every machine in the building.

What is Windows LAPS?

Windows LAPS (Local Administrator Password Solution) is a Windows feature that gives each PC's local admin account its own random password, rotates it on a schedule, and backs it up to Microsoft Entra ID or Active Directory. Authorized IT staff look it up when they need it. Nobody has to remember it, and no two machines share one.

It ships in Windows. Per Microsoft's documentation, it's supported on Windows 11 and on Windows 10 with the April 11, 2023 update or later, and it's available at no cost. Backing passwords up to Entra ID needs only Entra ID Free or higher.

If you're still running the old Microsoft LAPS add-on, plan the move. Microsoft deprecated it as of Windows 11 23H2, and newer Windows builds block it from installing.

How do you remove local admin rights without breaking work?

Do it in stages. The rollouts that go badly are the ones done in one weekend.

  1. Find out who's an admin today. Pull a report from your management tool, or run net localgroup administrators on a few machines. Expect more names than you thought.
  2. List what those people actually install. Usually it's a handful of apps: a PDF editor, a printer driver, a line-of-business update, Zoom.
  3. Package those apps. Push them from the Intune Company Portal or your RMM so users can install approved software without admin rights. See how we handle Intune management for small businesses.
  4. Turn on LAPS before you pull rights. That way IT has a working, unique admin password on every machine before anyone loses theirs.
  5. Remove rights in waves. In Intune, use a Local user group membership policy under Endpoint security > Account protection to set who belongs in each PC's Administrators group. On Active Directory, Group Policy does the same job. Start with one team, fix what breaks, then move on.
  6. Write an exception process. Developers and a few power users may need elevation. Give it to them through a separate admin account or a just-in-time elevation tool such as Intune Endpoint Privilege Management, which is licensed separately, never through their everyday login.

Expect a spike of "can you install this" requests for a couple of weeks. It drops off once the common apps are in the portal.

How do you turn on LAPS in Intune?

If your PCs are Entra joined or hybrid joined and managed in Intune, the setup is short. Microsoft's Intune LAPS guide covers the details.

  • Enable LAPS in the Entra admin center under device settings.
  • Create a policy in Intune under Endpoint security > Account protection, set the backup directory to Entra ID, and pick a rotation schedule and password length.
  • Decide who can read passwords. Per Microsoft, the built-in Cloud Device Administrator and Intune Administrator roles can. Helpdesk Administrator sees only metadata, so give your help desk a custom role if they need passwords. Rotating on demand also needs a custom Intune role.
  • On Windows 11 24H2 and later, Intune can create and manage a dedicated local admin account for you. On older builds, LAPS manages an account that already exists.

Turn on post-authentication reset. Windows LAPS can rotate the password automatically after the account is used, with a grace period to finish the job. A password a technician has seen is a password that's been exposed.

No Intune? Domain-joined PCs can back up to Active Directory with Group Policy instead. It's the same feature with a different control panel.

What about the owner's PC?

Same rule. Owners and executives are the most targeted people in the company, and their accounts open the most doors.

Give yourself a standard account for email and browsing. If you truly need admin rights, use a separate admin account you sign in to only when installing something.

This is the same idea behind privileged access management: nobody holds standing admin power they don't use every hour.

Frequently asked questions

Will removing admin rights stop users from working?

Not if you prepare. Most users never need admin rights for daily work.

The friction comes from software installs and updates, so package the common apps first and give people a self-service portal. The remaining requests go to the help desk, which takes minutes once LAPS is in place.

Is Windows LAPS free?

Yes. Windows LAPS is built into supported versions of Windows 10 and 11 at no extra cost.

Backing passwords up to Entra ID requires Entra ID Free or higher, which every Microsoft 365 tenant already has. Managing it through Intune requires an Intune license, which Business Premium includes.

How often should LAPS rotate passwords?

Pick a schedule your team will live with, such as every 30 days, and turn on automatic reset after use. The after-use reset matters more than the calendar.

A password a technician typed into a machine last Tuesday shouldn't still work next month.

Do cyber insurers care about local admin rights?

Yes. Applications regularly ask how you control privileged and administrator access.

If the honest answer is "everyone's an admin," expect a harder renewal. Our guide to cyber insurance requirements covers what carriers ask.

Not sure where you stand? Ask us for a complimentary security assessment.

What if one employee really needs admin rights?

Give them a second, separate admin account with multi-factor authentication, and keep their daily login standard. They sign in to the admin account only to install or configure something. That way a phishing click in email doesn't land with admin power.

Intune & Autopilot Deployment

Discuss intune & autopilot deployment for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore Intune & Autopilot Deployment 845-203-3914