The local administrator password solution (LAPS) is Jamf's implementation of a managed local administrator password solution. LAPS allows you to use Jamf Pro to automatically store, rotate, and view the randomized password of a managed local administrator account. This functionality is available in the Jamf Pro API and the Jamf Pro interface.
Rotating the local administrator account password using LAPS provides improved security when compared with using a static password. With the increasing risk of unauthorized access to sensitive data or systems, having unique local administrator passwords for each device is crucial to improving security. If all computers in an organization shared the same password, a single, compromised password could grant access to all of them.
The Jamf managed local administrator account password. The Jamf managed local administrator account is created on computers by selecting the following option in Jamf Pro: . This account's password is managed by the Jamf management framework. For more information, see Managed Local Administrator Accounts in the Jamf Pro Documentation.
This type of LAPS is called "Jamf management framework LAPS".
The managed local administrator account password from a Prestage enrollment. You can create an additional administrator account by selecting the following option in Jamf Pro: (). This account's password is managed by an MDM command. For more information, see "Provisioning Local Accounts during Automated Device Enrollment" in Automated Device Enrollment for Computers in the Jamf Pro Documentation.
This type of LAPS is called "MDM LAPS".
Do not use the same username for the managed local administrator account created in user-initiated enrollment settings and a managed local administrator account created in a PreStage enrollment. If the same username is used for both accounts, unexpected errors may occur during Automated Device Enrollment. In addition, the LAPS password will not be retrievable.
For more information about the Jamf Pro API, see Jamf Pro API Overview in the Jamf Developer Portal.