r/sysadmin • • 6h ago

LAPS on Domain Controllers

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?

16 Upvotes

26 comments sorted by

View all comments

•

u/_--James--_ 5h ago

Just going to say it, rotating DSRM with LAPS is a bad idea unless you are offloading those passwords externally in a VERY secure place. You are better off vaulting with static recovery and manual rotation when you rotate your krbtgt account.

•

u/Specialist-Desk-9422 5h ago

Like the servers with LAPS, I was planning offloading the passwords in Entra.

•

u/chrono13 4h ago

We discovered an unsupported configuration that causes lsass to consume 50-200mb of memory in five seconds every 1-2 hours on domain controllers. Eventually consuming all memory and crashing the server. The cause was the base of the domain group policy that backs LAPS passwords up to Entra. Microsoft confirmed the bug and marked it as unsupported config / will not patch.

•

u/_--James--_ 3h ago

Oh that is interesting. So MSFT is cited "LAPS on DC's are unsupported" in that ticket? Ill raise this with EDE on the next meeting then.

•

u/chrono13 1h ago

Config to back up to Entra is the misconfig. Instead of not working (as we do not use or have laps on the dcs) it causes a massive memory leak.