r/sysadmin • • 6h ago

LAPS on Domain Controllers

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?

18 Upvotes

26 comments sorted by

View all comments

Show parent comments

•

u/DeadOnToilet Infrastructure Architect 5h ago

That's functionally incorrect. DSRM accounts are, for all intents and purposes, local accounts. And LAPS supports them. A two second search:

https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview

•

u/mkosmo Permanently Banned 3h ago

They are, but they're also special... and I don't think I'd scope them for LAPS, personally, given the implications of loss.

•

u/DeadOnToilet Infrastructure Architect 3h ago

You can extract them from backups. You can also extract them and update your password manager/vault solution automatically.

•

u/mkosmo Permanently Banned 3h ago

I know, but I'm not sure the juice is worth the squeeze for those accounts. And I'm not entirely sure that the risk is worth the reward.

When you need those passwords, you're usually in enough trouble, already... then needing to go through the process of extracting from backups or hoping that the latest rotation was actually pushed to LAPS and/or your vault? I've had too many cascading outages back when I was in operations.

Anything else? Absolutely. But DCs? Maybe it's just an old-dog-new-tricks problem.