The following instructions describe how to enable MDM LAPS, turn on automatic password rotation, and configure password rotation frequency in the Jamf Pro interface. Keep the following in mind before enabling MDM LAPS:
When you select the checkbox, LAPS password management is enabled for managed local administrator accounts created via PreStage enrollment (MDM LAPS). This means the password for the account will be randomized the next time the computer submits inventory to Jamf Pro. This applies to an MDM-created managed local administrator account on both newly-enrolled computers and previously-enrolled computers.
When the managed local administrator account password is randomized and managed by LAPS, the global settings for password rotation will apply to the account. The account will remain managed by LAPS, even when the checkbox is deselected.
When you deselect the checkbox, passwords for managed local administrator accounts on newly enrolled computers created via PreStage enrollment will not have their passwords randomized and managed by LAPS.
Both Jamf management framework LAPS and MDM LAPS are now enabled and ready to be applied to managed computers.