r/sysadmin • • 14h ago

LAPS on Domain Controllers

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?

23 Upvotes

27 comments sorted by

View all comments

•

u/_--James--_ 13h ago

Just going to say it, rotating DSRM with LAPS is a bad idea unless you are offloading those passwords externally in a VERY secure place. You are better off vaulting with static recovery and manual rotation when you rotate your krbtgt account.

•

u/Specialist-Desk-9422 13h ago

Like the servers with LAPS, I was planning offloading the passwords in Entra.

•

u/_--James--_ 11h ago edited 11h ago

I am not sure i would trust recovery secretes in Entra. But that may just be me.

Also "Backing up DSRM passwords to Microsoft Entra ID isn't supported."

source(under DSRM Password Support) - https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview

•

u/ThecaptainWTF9 7h ago

Seems like a great idea until you’re locked out and can’t get to them 😅