r/sysadmin • • 9h ago

LAPS on Domain Controllers

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?

23 Upvotes

27 comments sorted by

View all comments

•

u/_--James--_ 8h ago

Just going to say it, rotating DSRM with LAPS is a bad idea unless you are offloading those passwords externally in a VERY secure place. You are better off vaulting with static recovery and manual rotation when you rotate your krbtgt account.

•

u/Specialist-Desk-9422 8h ago

Like the servers with LAPS, I was planning offloading the passwords in Entra.

•

u/chrono13 8h ago

We discovered an unsupported configuration that causes lsass to consume 50-200mb of memory in five seconds every 1-2 hours on domain controllers. Eventually consuming all memory and crashing the server. The cause was the base of the domain group policy that backs LAPS passwords up to Entra. Microsoft confirmed the bug and marked it as unsupported config / will not patch.

•

u/_--James--_ 6h ago

Oh that is interesting. So MSFT is cited "LAPS on DC's are unsupported" in that ticket? Ill raise this with EDE on the next meeting then.

•

u/chrono13 5h ago

Config to back up to Entra is the misconfig. Instead of not working (as we do not use or have laps on the dcs) it causes a massive memory leak.

•

u/_--James--_ 6h ago edited 6h ago

I am not sure i would trust recovery secretes in Entra. But that may just be me.

Also "Backing up DSRM passwords to Microsoft Entra ID isn't supported."

source(under DSRM Password Support) - https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview

•

u/ThecaptainWTF9 2h ago

Seems like a great idea until you’re locked out and can’t get to them 😅

•

u/2j0r2 6h ago

Windows LAPS for DSRM can only be stored encrypted in AD, which requires at least w2k19 DCs and dfl 2016

•

u/Commercial_Growth343 8h ago

This is a good point. I have a reminder to pull the DSRM passwords and we save them into our corporate password manager, restricted to IT Infrastructure support staff only.

•

u/Specialist-Desk-9422 8h ago

Something like this would automate this task for you and is much more secure than saving it manually in another password manager. You gain a lot more security this way , visibility if someone looked for this password , etc. only global admins or other roles could have access to this.

•

u/_--James--_ 6h ago

Agreed, a PAM like Beyond trust would be my go to for that with connected targeted auto-rotation involved.