Централизованное Управление Паролями Локальных Учетных Записей
Централизованное Управление Паролями Локальных Учетных Записей
Централизованное Управление Паролями Локальных Учетных Записей
management in AD DS
(LAPS)
Kirill Nikolaev
MCSE, MCITP
What is LAPS?
• A security tool to prevent lateral movement.
• Part of Microsoft’s POP-SLAM / PtH initiatives.
• Regularly generates unique, random password for a local user.
• Supported by Premier.
• Example:
• Single OS image deployed by HelpDesk.
What's in the box?
• Client Side Group Policy Extension (Managed computers)
• %ProgramFiles%\LAPS\CSE\AdmPwd.dll
• {D76B9641-3288-4f75-942D-087DE603E3EA}
Won't be cleaned up
when you delete a computer object.
Is not audited.
Control access
Delegation
1. Set-AdmPwdComputerSelfPermission -Identity <OU>
Delegation
2. Set-AdmPwdReadPasswordPermission -Identity <OU>
-AllowedPrincipals <Computers administrator(s)>
l es s
U s e
Delegation
3. Set-AdmPwdResetPasswordPermission -Identity <OU>
-AllowedPrincipals <Computers administrator(s)>
ms-Mcs-AdmPwd attribute
• Find-AdmPwdExtendedRights, to find everybody with access to it.
• By default – Domain Admins only.
• Deny: Nobody.
Deployment
• MSI-package (LAPS.x64.msi, LAPS.x86.msi)
• AD
• SCCM
• Manual
• What to read:
• https://technet.microsoft.com/security/advisory/3062591
• https://technet.microsoft.com/en-us/mt227395.aspx
• https://blogs.technet.microsoft.com/secguide/2014/09/02/blocking-remote-
use-of-local-accounts/
Kirill Nikolaev
MCSE, MCITP
https://exchange12rocks.org