Enabling LAPS in the Jamf Pro Interface - Technical Paper: Local Administrator Password Solution for Jamf Pro

Technical Paper: Local Administrator Password Solution for Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The following instructions describe how to enable MDM LAPS, turn on automatic password rotation, and configure password rotation frequency in the Jamf Pro interface. Keep the following in mind before enabling MDM LAPS:

  • When you select the checkbox, LAPS password management is enabled for managed local administrator accounts created via PreStage enrollment (MDM LAPS). This means the password for the account will be randomized the next time the computer submits inventory to Jamf Pro. This applies to an MDM-created managed local administrator account on both newly-enrolled computers and previously-enrolled computers.

  • When the managed local administrator account password is randomized and managed by LAPS, the global settings for password rotation will apply to the account. The account will remain managed by LAPS, even when the checkbox is deselected.

  • When you deselect the checkbox, passwords for managed local administrator accounts on newly enrolled computers created via PreStage enrollment will not have their passwords randomized and managed by LAPS.

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the Computer management section, click Security .
  3. Select the Enable LAPS for PreStage accounts checkbox.
  4. Choose a value from the Rotation Interval pop-up menu to define how often to automatically rotate passwords for managed local administrator accounts.

    The default value is "Never".

  5. Choose a value from the Rotation After Viewing Interval pop-up menu to automatically rotate passwords for managed local administrator accounts after they are viewed.

Both Jamf management framework LAPS and MDM LAPS are now enabled and ready to be applied to managed computers.