Using LAPS in the Jamf Pro Interface - Technical Paper: Local Administrator Password Solution for Jamf Pro

Technical Paper: Local Administrator Password Solution for Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The following instructions provide an example workflow for creating both a Jamf management framework LAPS account and an MDM LAPS account and using LAPS in the Jamf Pro interface. Depending your enrollment workflows, you may have only one LAPS account or none.

  1. In Jamf Pro, do the following:
    1. Navigate to Settings > User-initiated enrollment > Computers and select Create managed local administrator account.

      This will create the Jamf management framework LAPS account.

    2. Navigate to Computers > PreStage enrollments > Account Settings and select Create a managed local administrator account before Setup Assistant.

      This will create the MDM LAPS account.

  2. Enroll a computer via Automated Device Enrollment.
  3. To view the LAPS accounts, navigate to the computer's inventory record and click the Local User Accounts category.

    In this scenario, the computer should have two LAPS accounts. The "Source" column indicates the type of LAPS account.

  4. Click View to view the LAPS passwords.

    Viewing the LAPS passwords automatically triggers password rotation according to your LAPS settings in Settings > Computer management > Security.

  5. Click the History tab and then click the Managed Local Administrator Account History category to view all LAPS events that have occurred, including password viewing and rotation.