Local Administrator Password Solution

Also known as:LAPS

Local Administrator Password Solution: Management of individual, frequently changing local administrator passwords. This term is relevant for the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.

How it works and where it fits

Local Administrator Password Solution separates the subject, digital identity, authentication factor, and authorization decision. Authentication establishes who or what is presenting an identity; authorization then determines which action is permitted in the current context. Session state, device trust, request origin, and risk signals can further influence that decision.

Practical security relevance

Effective implementation requires a controlled identity lifecycle from creation through role and entitlement changes to suspension and removal. Strong authentication, least privilege, periodic recertification, and traceable logs are central. Controls must also identify abuse of legitimate accounts, because valid credentials alone do not prove that an action is legitimate.

  • Privileged Access ManagementPrivileged Access ManagementSecures, monitors, and controls accounts with extensive privileges.: Secures, monitors, and controls accounts with extensive privileges.
  • Active DirectoryActive DirectoryMicrosoft directory service for the centralized management of identities and resources.: Microsoft directory service for the centralized management of identities and resources.
  • Just-in-Time AccessJust-in-Time AccessGrants privileged rights only for a short, need-based period.: Grants privileged rights only for a short, need-based period.
  • Passwordless AuthenticationPasswordless AuthenticationAuthentication that does not rely on a shared password, such as through passkeys or hardware tokens.: Authentication that does not rely on a shared password, such as through passkeys or hardware tokens.