The following table shows differences between Jamf management framework LAPS and MDM LAPS:
Jamf management framework LAPS | MDM LAPS | |
|---|---|---|
| Enrollment method |
| Automated Device Enrollment Note: The management account created in the user-initiated enrollment settings is used for both user-initiated enrollment and Automated Device Enrollment. |
| Local administrator account creation method | Specified in user-initiated enrollment settings | PreStage enrollment settings |
| Enabled by default | ✔ | |
| Rotates local administrator account password | ✔ | ✔ |
| 29-character password | ✔ | ✔ |
| Preserves cryptographic user privileges during password rotation, if applicable | ✔ | |
| Preserves keychain password during rotation, if applicable | ✔ | |
| Rotation mechanism | Jamf management framework | MDM |
| When a pending rotation is processed | At next Jamf management framework check-in on the client computer | At next MDM check-in with Jamf Pro |
| Automatic password rotation enabled | ✔ Automatic password rotation cannot be disabled | Must be enabled globally via the /v2/local-admin-password/settings endpoint |
| Able to utilize accounts created before debut of the LAPS feature | ✔ Account migrated from computers table during upgrade from Jamf Pro 10.46.0–10.48.0 to Jamf Pro 10.49.0 or later | ✔ Collected as part of inventory update |