Module 21 · LAPS Bypass & Local Admin Password Strategy

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 13, 2026
6 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. LAPS (Local Administrator Password Solution) is Microsoft’s answer to the single most-exploited misconfiguration in Windows estates: the same local Administrator password set on every workstation by the imaging process. LAPS randomises that password per-machine and stores it in AD. But the protection only works if you have configured the ACLs correctly, and bypassing LAPS is a routine pentest finding when those ACLs are wrong. This module covers how LAPS works, how attackers bypass it, and how to deploy it without leaving back doors.

Why this module exists. Before LAPS, the canonical AD post-exploitation move was: dump the local Administrator hash from any workstation, then Pass-the-Hash to every other workstation in the estate. LAPS killed that move by making each machine’s password independent. But LAPS adoption is incomplete in Indian enterprises (typically 60-80% coverage in audits) and the ACLs around the LAPS attribute are routinely misconfigured. This module is the practical guide.

What LAPS actually is — two generations

“LAPS” today means two related but distinct products:

  • Legacy LAPS (originally released 2015): client-side .msi installed on each managed machine; the password is stored in clear text in the ms-Mcs-AdmPwd attribute on the computer object. ACLs on that attribute control who can read.
  • Windows LAPS (built into Windows 10/11 and Server 2019+ since April 2023 KB): client-side functionality baked into the OS; password stored encrypted (DPAPI-NG with a designated decryptor) in msLAPS-EncryptedPassword, optionally with password history in msLAPS-EncryptedPasswordHistory.

Many estates run a hybrid for ~2 years during migration. Hybrid estates are the highest-risk because admins forget the legacy attributes still exist on older machines.

Need a real pentest?

Get a VAPT scoping call

Senior practitioner-led VAPT — not a checklist run by juniors. CVSS-scored findings, free retest, attestation letter. India's SMBs and SaaS teams.

Book VAPT scoping call Replies in 4 working hrs · India-only · Senior consultants