Loading_
Loading_
Windows LAPS rollout and rotation across 26,000 endpoints with break-glass retrieval and full audit.
Measured outcomes
100%
Unique local admin passwords
24h
Rotation interval
−100%
Shared credential exposure
8 days
Full estate rollout
Local administrator passwords were shared, static and identical across large parts of the estate — one compromised endpoint meant lateral movement everywhere.
We deployed Windows LAPS with automated rotation, tiered retrieval permissions, and an approval-gated break-glass path that records who read which password and why.
Headline result
0k
endpoints rotated
Tags
Five capabilities that define the system. Each one exists because something specific was broken.
Ring-based deployment with automatic halt if failure rate crosses a threshold.
Who can read which tier of machine is enforced in AD, not by convention.
Emergency retrieval requires justification and a second approver, and rotates immediately after use.
Continuous evidence of rotation coverage and age distribution.
Safe transition from legacy Microsoft LAPS with overlap validation.
Native Windows LAPS with a governance layer over retrieval — the secret store stays in AD/Entra, the workflow sits above it.
3 components
Managed devices via Intune, domain-only devices via GPO.
3 components
Encrypted at rest; retrieval rights modelled on the admin tier structure.
4 components
Reading a password is an event, not a query.
No mystery components. Everything below is either open source or a platform you already own.
Interactive mock-ups of the shipped interface. The live environment is available during a demo session.
Coverage and rotation age by ring
The running environment is available during a booked session — including a sandbox tenant you can drive yourself.
The real sequence, in order. Steps with a command are copy-pasteable.
Apply the Windows LAPS AD schema extension in a maintenance window.
$Update-LapsADSchema -VerboseDelegate read rights per admin tier and remove inherited access.
$Set-LapsADReadPasswordPermission -Identity "OU=Tier1,DC=corp,DC=local" -AllowedPrincipals "Tier1-Admins"Push the Intune configuration profile to ring 1, then widen.
Stand up the retrieval portal and disable direct directory reads.
Published rather than hidden behind a call. Volume and multi-year terms move these numbers.
Governance layer
$0.45per endpoint / month
Rollout service
from $19kone-time
Need this scoped against your estate? We will size it properly, in writing, within a week.
Request a quoteWe will walk you through the architecture, the trade-offs we made, and what would change for your environment.