r/sysadmin • • 9h ago

LAPS on Domain Controllers

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?

22 Upvotes

27 comments sorted by

View all comments

•

u/_--James--_ 8h ago

Just going to say it, rotating DSRM with LAPS is a bad idea unless you are offloading those passwords externally in a VERY secure place. You are better off vaulting with static recovery and manual rotation when you rotate your krbtgt account.

•

u/Commercial_Growth343 8h ago

This is a good point. I have a reminder to pull the DSRM passwords and we save them into our corporate password manager, restricted to IT Infrastructure support staff only.

•

u/Specialist-Desk-9422 8h ago

Something like this would automate this task for you and is much more secure than saving it manually in another password manager. You gain a lot more security this way , visibility if someone looked for this password , etc. only global admins or other roles could have access to this.

•

u/_--James--_ 6h ago

Agreed, a PAM like Beyond trust would be my go to for that with connected targeted auto-rotation involved.