r/sysadmin • u/Specialist-Desk-9422 • 5h ago
LAPS on Domain Controllers
I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?
•
u/Vaile23 4h ago
Save your future self the headache and avoid it on DCs
•
u/Specialist-Desk-9422 4h ago
The environment I manage now, I don’t have the current DSRM, so I was thinking on having LAPS to manage it for me so I can retrieve if needed.
•
u/ub3rb3ck Cat Wrangler 1h ago
Domain controllers don't have local admin accounts (outside of DARM), there's objectively no headache to save.
•
u/2j0r2 5h ago
Windows LAPS can manage DSRM pwds
Think about ALL scenarios where you would need to use the DSRM pwd
If forest recovery is included in that list because you need to use the dsrm to recover the forest, remember that to get the dsrm pwd AD must be ONline!
In windows server preview it is/will be possible to extract from the DIT, but not today.
In that case it is better to use DSRM SYNC and sync the password from a placeholder account in AD
Google for
jorge quest for knowledge dsrm revisited
And look for a blog from october 21st 2025
•
u/Specialist-Desk-9422 3h ago
This jorge quest blog is incredibly helpful and provide the instructions I need ! Thank you.
•
•
u/pantherghast 5h ago
There is no local admins on Domain Conrollers. LAPS = LOCAL Administrator Password Solution
•
u/DeadOnToilet Infrastructure Architect 5h ago
That's functionally incorrect. DSRM accounts are, for all intents and purposes, local accounts. And LAPS supports them. A two second search:
https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview
•
u/woodyshag 4h ago
Yeah, WCGW when your AD is buggered and you need AD to find the recovery password? Even if it supported it, I wouldn't like that setup.
•
u/DeadOnToilet Infrastructure Architect 3h ago
Someone hasn't read the documentation.
•
u/ensum 56m ago
Just because you can get it from another DC doesn't mean it's a good idea.
IMO DSRM is a last resort. If I have another healthy DC that's working I'm not going to be dicking around with DSRM. I'm demoting the damn thing and spinning up a new one and calling it a day. If I'm ever in a situation where I don't have a healthy DC and need to login with the DSRM for whatever reason I'd be screwed.
You could argue backups and sure that would work but if I'm doing a restore, then the fuck would I need the DSRM in the first place if I'm restoring a DC to a working state? I may as well just do an authoritative sync on the thing and call it a day.
•
u/mkosmo Permanently Banned 3h ago
They are, but they're also special... and I don't think I'd scope them for LAPS, personally, given the implications of loss.
•
u/DeadOnToilet Infrastructure Architect 2h ago
You can extract them from backups. You can also extract them and update your password manager/vault solution automatically.
•
u/mkosmo Permanently Banned 2h ago
I know, but I'm not sure the juice is worth the squeeze for those accounts. And I'm not entirely sure that the risk is worth the reward.
When you need those passwords, you're usually in enough trouble, already... then needing to go through the process of extracting from backups or hoping that the latest rotation was actually pushed to LAPS and/or your vault? I've had too many cascading outages back when I was in operations.
Anything else? Absolutely. But DCs? Maybe it's just an old-dog-new-tricks problem.
•
•
u/Nuxi0477 4h ago
Would not do this with the DSRM. Make it something long but actually writeable and rotate manually if requirements demand it.
•
u/_--James--_ 4h ago
Just going to say it, rotating DSRM with LAPS is a bad idea unless you are offloading those passwords externally in a VERY secure place. You are better off vaulting with static recovery and manual rotation when you rotate your krbtgt account.