Create a LAPS Library Item
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Navigate to Library
Select LAPS
Name the Library Item
Assign to Blueprints
Configure the LAPS Library Item
These settings control the passwords Iru generates. Configure them using the steps below.Import from Passcode

Select a Passcode Library Item

Review imported Passcode settings

Minimum passcode length
Maximum passcode length

Disallow simple passcode
123 or CBA) or more than three repeating characters (such as 111 or AAA). Enabled by default.Require alphanumeric passcode

Minimum complex characters
& % $ #. Default: 4. Range: 0 to 36.Maximum complex characters

Automatically rotate after (days)
Automatically rotate after viewing (hours)

Import from ADE

Select an ADE integration

Review imported admin users

Admin users to manage

Update Initial password if it changes outside LAPS
Save
View a device’s password
Help Desk or higher can reveal a LAPS password. Secrets Auditor and Auditor can see that a password exists but cannot reveal it. Displaying a password logs the view and, if a LAPS Library Item is assigned, starts Automatically rotate after viewing (hours).Open the device record
Select View local admin password

Choose the account
Display the password

Hide the password
Copy the password
Click Done

View activity records
Local admin password activity is recorded on the device record Activity tab and in Unified Activity. These events do not appear on the Activity Page.Device record
On the device record Activity tab, Iru records when a local admin password is viewed, rotated, or fails to rotate.Review Local Admin Password Viewed

Review Local Admin Password Rotated

Review Local Admin Password Rotation Failed

Unified Activity
Unified Activity records when a local admin password is viewed and when it is updated, including success and failure.Filter Unified Activity

Review Local admin password viewed

Review Local admin password updated

Review a failed rotation

Go to device
Considerations
Admin accounts only
One LAPS Library Item per device
Current password is required
Re-enrollment rotates at the next check-in
Set Auto Admin Password is unavailable
Who can reveal a password
Best Practices
Reuse your Passcode settings
Match your compliance requirements
Review rotation activity
Troubleshooting
No admin account to import from 'ADE'.
No admin account to import from 'ADE'.
- The ADE integration does not define a local administrator account
- In Automated Device Enrollment, confirm a local admin account is configured, then import again
Admin user from 'ADE' is already in the list.
Admin user from 'ADE' is already in the list.
- You already imported from that ADE integration
- You added the same username manually
- Keep the existing row. Iru does not add a duplicate.
A password failed to rotate
A password failed to rotate
Reason: <cause>) or the device record Activity tab (<username>: <cause>).Possible causes:- The Reason field names the cause, such as a locked keychain
- The account is not a local administrator
- Iru’s stored current password does not match the device
- Confirm the account is an administrator. LAPS does not manage standard accounts
- There is no automatic retry. The next attempt follows Automatically rotate after (days)
- If the stored password is out of sync, contact Iru Support
Viewed the password, but it did not rotate
Viewed the password, but it did not rotate
- No LAPS Library Item was assigned to the device at the time of viewing
- Assign a LAPS Library Item if you want Automatically rotate after viewing (hours) and Automatically rotate after (days) going forward
- The view is still logged even when Automatically rotate after viewing (hours) does not start
Set Auto Admin Password is missing from device actions
Set Auto Admin Password is missing from device actions
- LAPS is assigned to this device, so the conflicting MDM command is hidden
- Expected when LAPS is assigned. Use View local admin password instead
- Remove LAPS from the device’s Blueprint only if you need the Set Auto Admin Password action
An admin account will not rotate
An admin account will not rotate
- The account is not an administrator
- The account is not present on the device
- The current password in the Library Item does not match the account on the device
- Confirm the account is a local administrator
- Confirm the username matches the account on the Mac
- Provide the current password on first assignment so Iru can take over the account