LAPS Comparison Table - Technical Paper: Local Administrator Password Solution for Jamf Pro

Technical Paper: Local Administrator Password Solution for Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The following table shows differences between Jamf management framework LAPS and MDM LAPS:

Jamf management framework LAPS

MDM LAPS

Enrollment method
  • Automated Device Enrollment

  • User-initiated enrollment

Automated Device Enrollment
Note:

The management account created in the user-initiated enrollment settings is used for both user-initiated enrollment and Automated Device Enrollment.

Local administrator account creation method

Specified in user-initiated enrollment settings

PreStage enrollment settings

Enabled by default
Rotates local administrator account password
29-character password
Preserves cryptographic user privileges during password rotation, if applicable

Preserves keychain password during rotation, if applicable

Rotation mechanism

Jamf management framework

MDM

When a pending rotation is processedAt next Jamf management framework check-in on the client computer At next MDM check-in with Jamf Pro
Automatic password rotation enabled

Automatic password rotation cannot be disabled

Must be enabled globally via the /v2/local-admin-password/settings endpoint

Able to utilize accounts created before debut of the LAPS feature

Account migrated from computers table during upgrade from Jamf Pro 10.46.0–10.48.0 to Jamf Pro 10.49.0 or later

Collected as part of inventory update