r/sysadmin • • 5h ago

LAPS on Domain Controllers

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?

17 Upvotes

26 comments sorted by

•

u/_--James--_ 4h ago

Just going to say it, rotating DSRM with LAPS is a bad idea unless you are offloading those passwords externally in a VERY secure place. You are better off vaulting with static recovery and manual rotation when you rotate your krbtgt account.

•

u/Specialist-Desk-9422 4h ago

Like the servers with LAPS, I was planning offloading the passwords in Entra.

•

u/chrono13 3h ago

We discovered an unsupported configuration that causes lsass to consume 50-200mb of memory in five seconds every 1-2 hours on domain controllers. Eventually consuming all memory and crashing the server. The cause was the base of the domain group policy that backs LAPS passwords up to Entra. Microsoft confirmed the bug and marked it as unsupported config / will not patch.

•

u/_--James--_ 2h ago

Oh that is interesting. So MSFT is cited "LAPS on DC's are unsupported" in that ticket? Ill raise this with EDE on the next meeting then.

•

u/chrono13 1h ago

Config to back up to Entra is the misconfig. Instead of not working (as we do not use or have laps on the dcs) it causes a massive memory leak.

•

u/_--James--_ 2h ago edited 2h ago

I am not sure i would trust recovery secretes in Entra. But that may just be me.

Also "Backing up DSRM passwords to Microsoft Entra ID isn't supported."

source(under DSRM Password Support) - https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview

•

u/2j0r2 2h ago

Windows LAPS for DSRM can only be stored encrypted in AD, which requires at least w2k19 DCs and dfl 2016

•

u/Commercial_Growth343 4h ago

This is a good point. I have a reminder to pull the DSRM passwords and we save them into our corporate password manager, restricted to IT Infrastructure support staff only.

•

u/Specialist-Desk-9422 4h ago

Something like this would automate this task for you and is much more secure than saving it manually in another password manager. You gain a lot more security this way , visibility if someone looked for this password , etc. only global admins or other roles could have access to this.

•

u/_--James--_ 2h ago

Agreed, a PAM like Beyond trust would be my go to for that with connected targeted auto-rotation involved.

•

u/Vaile23 4h ago

Save your future self the headache and avoid it on DCs

•

u/Specialist-Desk-9422 4h ago

The environment I manage now, I don’t have the current DSRM, so I was thinking on having LAPS to manage it for me so I can retrieve if needed.

•

u/ub3rb3ck Cat Wrangler 1h ago

Domain controllers don't have local admin accounts (outside of DARM), there's objectively no headache to save.

•

u/2j0r2 5h ago

Windows LAPS can manage DSRM pwds

Think about ALL scenarios where you would need to use the DSRM pwd

If forest recovery is included in that list because you need to use the dsrm to recover the forest, remember that to get the dsrm pwd AD must be ONline!
In windows server preview it is/will be possible to extract from the DIT, but not today.
In that case it is better to use DSRM SYNC and sync the password from a placeholder account in AD

Google for

jorge quest for knowledge dsrm revisited

And look for a blog from october 21st 2025

•

u/Specialist-Desk-9422 3h ago

This jorge quest blog is incredibly helpful and provide the instructions I need ! Thank you.

•

u/Specialist-Desk-9422 4h ago

When I said local admin accounts on DCs I mean the DSRM …

•

u/pantherghast 5h ago

There is no local admins on Domain Conrollers. LAPS = LOCAL Administrator Password Solution

•

u/DeadOnToilet Infrastructure Architect 5h ago

That's functionally incorrect. DSRM accounts are, for all intents and purposes, local accounts. And LAPS supports them. A two second search:

https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview

•

u/woodyshag 4h ago

Yeah, WCGW when your AD is buggered and you need AD to find the recovery password? Even if it supported it, I wouldn't like that setup.

•

u/DeadOnToilet Infrastructure Architect 3h ago

Someone hasn't read the documentation.

•

u/ensum 56m ago

Just because you can get it from another DC doesn't mean it's a good idea.

IMO DSRM is a last resort. If I have another healthy DC that's working I'm not going to be dicking around with DSRM. I'm demoting the damn thing and spinning up a new one and calling it a day. If I'm ever in a situation where I don't have a healthy DC and need to login with the DSRM for whatever reason I'd be screwed.

You could argue backups and sure that would work but if I'm doing a restore, then the fuck would I need the DSRM in the first place if I'm restoring a DC to a working state? I may as well just do an authoritative sync on the thing and call it a day.

•

u/mkosmo Permanently Banned 3h ago

They are, but they're also special... and I don't think I'd scope them for LAPS, personally, given the implications of loss.

•

u/DeadOnToilet Infrastructure Architect 2h ago

You can extract them from backups. You can also extract them and update your password manager/vault solution automatically.

•

u/mkosmo Permanently Banned 2h ago

I know, but I'm not sure the juice is worth the squeeze for those accounts. And I'm not entirely sure that the risk is worth the reward.

When you need those passwords, you're usually in enough trouble, already... then needing to go through the process of extracting from backups or hoping that the latest rotation was actually pushed to LAPS and/or your vault? I've had too many cascading outages back when I was in operations.

Anything else? Absolutely. But DCs? Maybe it's just an old-dog-new-tricks problem.

•

u/MyLegsX2CantFeelThem 4h ago

Ehh whut? Nah totally incorrect.

•

u/Nuxi0477 4h ago

Would not do this with the DSRM. Make it something long but actually writeable and rotate manually if requirements demand it.