> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure the LAPS Library Item

> Set up the LAPS Library Item in Iru Endpoint to rotate and securely store local administrator passwords on managed Mac computers across your fleet.

<Callout icon="apple" color="#B84A7A" iconType="regular">This Library Item is available for Mac computers</Callout>

The **LAPS** (Local Administrator Password Solution) Library Item rotates passwords for the local administrators you define in this Library Item and stores them securely in Iru. Each Mac gets unique passwords for those accounts on a schedule you control, instead of one static admin password across the fleet.

LAPS does not create user accounts. It only rotates passwords for existing local administrators. Create those accounts by provisioning a local administrator (Auto Admin) in an [Automated Device Enrollment Library Item](/en/endpoint/enrollment/apple/configuring-apple-enrollment), or with the [Create User Accounts](/en/endpoint/blueprints/parameters/create-user-accounts) Blueprint Parameter.

This Library Item is enforced by the [Iru Agent](/en/endpoint/agent/iru-agent-and-mdm#about-the-macos-agent), so it works independently of [Apple's MDM protocol](/en/endpoint/agent/iru-agent-and-mdm#about-the-mdm-framework).

<Note>
  You must provide the existing password for each local administrator you define in this Library Item. Iru uses it to preserve SecureToken and volume ownership on Apple silicon.
</Note>

## Create a LAPS Library Item

To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article.

<Steps>
  <Step title="Navigate to Library">
    Navigate to the **Library** and select **Add Library Item**.
  </Step>

  <Step title="Select LAPS">
    Search for and select **LAPS**.
  </Step>

  <Step title="Name the Library Item">
    Give the Library Item a **Name**.
  </Step>

  <Step title="Assign to Blueprints">
    Assign it to one or more **Blueprints**.
  </Step>
</Steps>

## Configure the LAPS Library Item

These settings control the passwords Iru generates. Configure them using the steps below.

<Steps>
  <Step title="Import from Passcode">
    In **Password complexity**, optionally use **Import from Passcode** to copy complexity settings from a [Passcode](/en/endpoint/library/library-items-profiles/configure-the-passcode-library-item) Library Item already in your Library. You can import from a **Passcode** Library Item only, not from **Android Work Profile Passcode**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-import-from-passcode.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=e5d6ee5fc9f79a942ab228fae35785f4" alt="Password complexity section with Import from Passcode" width="1990" height="570" data-path="assets/media/images/iru-laps-import-from-passcode.png" />
    </Frame>

    If there is no compatible Passcode Library Item to import from, **Import from Passcode** is disabled and shows **No Library Items available**.

    <Note>
      macOS requires passwords on the device to comply with the passcode policy, so importing from an existing Passcode Library Item keeps LAPS aligned with that policy.
    </Note>
  </Step>

  <Step title="Select a Passcode Library Item">
    Search by name, then select the Passcode Library Item.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-import-from-passcode-select.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=7d72f853cbb38197e4d228b43820991d" alt="Import from Passcode search with a Passcode Library Item in the results" width="678" height="310" data-path="assets/media/images/iru-laps-import-from-passcode-select.png" />
    </Frame>
  </Step>

  <Step title="Review imported Passcode settings">
    When the import succeeds, matching settings show an **Imported** badge. You can still change any value after import.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-import-from-passcode-imported-settings.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=77755f1f9b345cd27a6f2a1a999140ce" alt="Password complexity settings with Imported badges after importing from Passcode" width="924" height="1064" data-path="assets/media/images/iru-laps-import-from-passcode-imported-settings.png" />
    </Frame>
  </Step>

  <Step title="Minimum passcode length">
    Set **Minimum passcode length** to the minimum overall length of the passcode. Default: **8**. Range: **1** to **36**.
  </Step>

  <Step title="Maximum passcode length">
    Set **Maximum passcode length** to the maximum overall length of the passcode. Default: **15**. Range: **1** to **36**. Must be at least **Minimum passcode length**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-min-and-max-passcode-length.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=ff40ec12c487bfa9371bcf6c20829190" alt="Minimum passcode length and Maximum passcode length settings" width="1548" height="396" data-path="assets/media/images/iru-laps-min-and-max-passcode-length.png" />
    </Frame>
  </Step>

  <Step title="Disallow simple passcode">
    Select **Disallow simple passcode** so passcodes cannot have more than two sequential characters (such as `123` or `CBA`) or more than three repeating characters (such as `111` or `AAA`). Enabled by default.
  </Step>

  <Step title="Require alphanumeric passcode">
    Select **Require alphanumeric passcode** to require letters as well as numbers. Enabled by default.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-simple-passcode-require-alphanumeric.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=aa1f5a6e671fa05de404e932e431ee01" alt="Disallow simple passcode and Require alphanumeric passcode settings" width="1986" height="286" data-path="assets/media/images/iru-laps-simple-passcode-require-alphanumeric.png" />
    </Frame>
  </Step>

  <Step title="Minimum complex characters">
    Set **Minimum complex characters** to the minimum number of complex characters that a passcode must contain. A complex character is a character other than a number or a letter, such as `& % $ #`. Default: **4**. Range: **0** to **36**.
  </Step>

  <Step title="Maximum complex characters">
    Set **Maximum complex characters** to the maximum number of complex characters that a passcode may contain. Default: **6**. Range: **1** to **36**. Must be at least **Minimum complex characters**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-min-and-max-complex-characters.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=9addabdbfb73d7c8c652ed3f311bd73a" alt="Minimum complex characters and Maximum complex characters settings" width="1964" height="406" data-path="assets/media/images/iru-laps-min-and-max-complex-characters.png" />
    </Frame>
  </Step>

  <Step title="Automatically rotate after (days)">
    Set **Automatically rotate after (days)** to how often local admin passwords rotate on devices and are securely stored with Iru, regardless of **Automatically rotate after viewing (hours)**. Range: **1** to **90** days. Default: **30** days.
  </Step>

  <Step title="Automatically rotate after viewing (hours)">
    Set **Automatically rotate after viewing (hours)** to how soon a viewed local admin password rotates. This setting runs independently of **Automatically rotate after (days)**. Range: **1** to **24** hours. Default: **2** hours.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-password-rotation-settings.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=099c6666b0be8f0a61964f1baff0b5e5" alt="Password rotation settings" width="1954" height="556" data-path="assets/media/images/iru-laps-password-rotation-settings.png" />
    </Frame>
  </Step>

  <Step title="Import from ADE">
    In **Admin users to manage**, optionally use **Import from ADE** to populate accounts from an [Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) integration.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-import-from-ade.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=8916ae327a534e4594bba480b88e6d7d" alt="Admin users to manage section with Import from ADE" width="1994" height="462" data-path="assets/media/images/iru-laps-import-from-ade.png" />
    </Frame>
  </Step>

  <Step title="Select an ADE integration">
    Search by name, then select the ADE integration.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-import-from-ade-select.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=91b6f1d56a55ed907940abdc9f780501" alt="Import from ADE search listing ADE integrations" width="682" height="440" data-path="assets/media/images/iru-laps-import-from-ade-select.png" />
    </Frame>
  </Step>

  <Step title="Review imported admin users">
    When the import succeeds, Iru shows **Imported settings from** the ADE integration name, and an **Imported** badge appears below **+ Add user**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-import-from-ade-imported.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=24271c90d449de649e547f9c16cbef56" alt="Admin users with an Imported badge after importing from ADE" width="1346" height="334" data-path="assets/media/images/iru-laps-import-from-ade-imported.png" />
    </Frame>
  </Step>

  <Step title="Admin users to manage">
    Add local administrator accounts whose passwords this LAPS policy should manage. Each row defines a **Username** and its **Initial password**. If the account is present on the device, the password will be rotated.

    Use **+ Add user** to add another row. Use the trash control on a row to remove it. Use the eye icon on **Initial password** to show or hide the value while you are setting or updating it.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-admin-users.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=53a6ceeabbe82b2658d79eafeea1d636" alt="Admin users to manage with Username and Initial password rows" width="2004" height="556" data-path="assets/media/images/iru-laps-admin-users.png" />
    </Frame>

    <Note>
      Passwords in **Admin users** are only viewable with the eye icon while you are setting the initial value or updating it. After you save, you cannot view the existing password in the Library Item.
    </Note>
  </Step>

  <Step title="Update Initial password if it changes outside LAPS">
    Once a device has had LAPS assigned, you do not need to re-enter the password on later edits to the Library Item. If that account's initial password changes outside LAPS, such as the password in [Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) or the [Create User Accounts](/en/endpoint/blueprints/parameters/create-user-accounts) Blueprint Parameter, update **Initial password** here so it matches what is set on the device now.
  </Step>

  <Step title="Save">
    Click **Save**.
  </Step>
</Steps>

## View a device's password

Help Desk or higher can reveal a LAPS password. Secrets Auditor and Auditor can see that a password exists but cannot reveal it. Displaying a password logs the view and, if a LAPS Library Item is assigned, starts **Automatically rotate after viewing (hours)**.

<Steps>
  <Step title="Open the device record">
    Navigate to **Devices** in the Iru Endpoint web app and select the Mac.
  </Step>

  <Step title="Select View local admin password">
    Open the **Device Action Menu** (ellipsis) in the upper right of the device record and select **View local admin password**. This action is available for any device that has ever had a LAPS password, including a device that is currently erased or locked.

    <Frame>
      <img src="https://mintcdn.com/iru/QuVDBLylYVO2hq43/assets/media/images/iru-view-local-admin-password-device-action.png?fit=max&auto=format&n=QuVDBLylYVO2hq43&q=85&s=b51e1fbf55700cdef43cccb72c10d27d" alt="Device Action Menu with View local admin password selected" width="598" height="376" data-path="assets/media/images/iru-view-local-admin-password-device-action.png" />
    </Frame>
  </Step>

  <Step title="Choose the account">
    In the **View local admin password** dialog, use **Select an admin user to view its password** to choose the account if more than one is managed on the device.
  </Step>

  <Step title="Display the password">
    Click the eye icon to display the current local admin password. That click logs who viewed the password and when, and starts **Automatically rotate after viewing (hours)**. The dialog states that after the password is displayed, it rotates on the device after that configured time.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-select-view-cancel.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=1aa70fad3814ae33cdf9134095a4b789" alt="View local admin password dialog with account selection, eye icon, and Cancel" width="1042" height="646" data-path="assets/media/images/iru-laps-select-view-cancel.png" />
    </Frame>

    <Note>
      If no LAPS Library Item is assigned at the time you view, Iru warns that **Automatically rotate after viewing (hours)** will not apply. The view is still logged.
    </Note>
  </Step>

  <Step title="Hide the password">
    After the password is displayed, click the eye icon with a line through it to hide the password.
  </Step>

  <Step title="Copy the password">
    Click the copy icon to copy the password.
  </Step>

  <Step title="Click Done">
    Click **Done** when you are finished.

    <Frame>
      <img src="https://mintcdn.com/iru/QuVDBLylYVO2hq43/assets/media/images/iru-view-local-admin-password-select-view-copy-password.png?fit=max&auto=format&n=QuVDBLylYVO2hq43&q=85&s=c95b737998ebf3baee163cbb7551a0f4" alt="View local admin password dialog after display, with hide and copy" width="1040" height="640" data-path="assets/media/images/iru-view-local-admin-password-select-view-copy-password.png" />
    </Frame>
  </Step>
</Steps>

### View activity records

Local admin password activity is recorded on the device record **Activity** tab and in [Unified Activity](/en/iru/platform-overview/unified-activity). These events do not appear on the [Activity Page](/en/endpoint/devices/activity-page).

#### Device record

On the device record **Activity** tab, Iru records when a local admin password is viewed, rotated, or fails to rotate.

<Steps>
  <Step title="Review Local Admin Password Viewed">
    A **Local Admin Password Viewed** entry shows the local admin username, who viewed the password, the device, and when.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-local-admin-password-viewed-activity.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=f1c6ead1d7c5356e0a3c5522c586baaf" alt="Device record Activity showing Local Admin Password Viewed" width="2112" height="428" data-path="assets/media/images/iru-laps-local-admin-password-viewed-activity.png" />
    </Frame>
  </Step>

  <Step title="Review Local Admin Password Rotated">
    A **Local Admin Password Rotated** entry shows the local admin username, the Blueprint, the device, and when.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-local-admin-password-rotated-device-activity.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=8ff8ae12c9c8d43596684cf29b119c84" alt="Device record Activity showing Local Admin Password Rotated" width="3140" height="136" data-path="assets/media/images/iru-laps-local-admin-password-rotated-device-activity.png" />
    </Frame>
  </Step>

  <Step title="Review Local Admin Password Rotation Failed">
    A **Local Admin Password Rotation Failed** entry shows the local admin username, a reason, the Blueprint, the device, and when.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-local-admin-password-rotation-failed-device-activity.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=7cab03267666e4acba2200e9c4e6cb84" alt="Device record Activity showing Local Admin Password Rotation Failed" width="3172" height="142" data-path="assets/media/images/iru-laps-local-admin-password-rotation-failed-device-activity.png" />
    </Frame>
  </Step>
</Steps>

#### Unified Activity

Unified Activity records when a local admin password is viewed and when it is updated, including success and failure.

<Steps>
  <Step title="Filter Unified Activity">
    In Unified Activity, open **Activity type**, search **Local admin**, and under **Endpoint** select **Local admin password viewed**, **Local admin password updated**, or both. Click **Apply**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-unified-activity-filters.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=c6d1e2fbd71d3d798c7a16035116f80b" alt="Unified Activity type filter for Local admin password viewed and Local admin password updated" width="636" height="510" data-path="assets/media/images/iru-laps-unified-activity-filters.png" />
    </Frame>
  </Step>

  <Step title="Review Local admin password viewed">
    A **Local admin password viewed** entry shows the local admin username, who viewed the password, and when.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-unified-activity-local-admin-password-viewed.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=c4bac050f40031df24ca9992cf84d12f" alt="Unified Activity showing Local admin password viewed" width="1994" height="420" data-path="assets/media/images/iru-laps-unified-activity-local-admin-password-viewed.png" />
    </Frame>
  </Step>

  <Step title="Review Local admin password updated">
    Expand a **Local admin password updated** entry. A successful rotation shows **Rotated for** the local admin username. Details include **Device**, **Local admin user**, **Outcome** (**Local admin password rotated**), and **Completed at**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-unified-activity-local-admin-password-updated-succeeded.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=df7db430f2079cebb24ceeb563ab508b" alt="Unified Activity showing Local admin password updated after a successful rotation" width="2148" height="428" data-path="assets/media/images/iru-laps-unified-activity-local-admin-password-updated-succeeded.png" />
    </Frame>
  </Step>

  <Step title="Review a failed rotation">
    A failed rotation uses the same **Local admin password updated** activity type. It shows **Rotation failed for** the local admin username. Details include **Outcome** (**Local admin password rotation failed**) and **Reason**.

    <Frame>
      <img src="https://mintcdn.com/iru/tQKdgadUiq5lCg8T/assets/media/images/iru-laps-unified-activity-local-admin-password-updated-failed.png?fit=max&auto=format&n=tQKdgadUiq5lCg8T&q=85&s=25b746b2b473e3ac718a0f777c8c5b2f" alt="Unified Activity showing Local admin password updated when rotation failed" width="2154" height="476" data-path="assets/media/images/iru-laps-unified-activity-local-admin-password-updated-failed.png" />
    </Frame>
  </Step>

  <Step title="Go to device">
    Click the ellipsis (**…**) next to the activity entry and select **Go to device** to open the related device record.
  </Step>
</Steps>

## Considerations

<CardGroup cols={2}>
  <Card title="Admin accounts only" icon="user">
    LAPS only manages local administrator accounts. Standard accounts are rejected with an error.
  </Card>

  <Card title="One LAPS Library Item per device" icon="clone">
    A device can have one LAPS Library Item assigned. Assigning a second Library Item is not supported.
  </Card>

  <Card title="Current password is required" icon="key">
    You must provide the existing password for each local administrator you define in this Library Item. Iru uses it to preserve SecureToken and volume ownership on Apple silicon. If Iru's record of a device's current password falls out of sync, [contact Iru Support](/en/iru/iru-support/access-to-iru-support). Without SecureToken, that account cannot unlock FileVault after a restart.
  </Card>

  <Card title="Re-enrollment rotates at the next check-in" icon="rotate">
    Re-enrolling a device rotates its password at the next check-in, not on whatever was left of **Automatically rotate after (days)**.
  </Card>

  <Card title="Set Auto Admin Password is unavailable" icon="lock">
    The [Set Auto Admin Account Password](/en/endpoint/devices/device-actions/set-the-auto-admin-account-password) device action is not available when LAPS is assigned. LAPS manages that password.
  </Card>

  <Card title="Who can reveal a password" icon="eye">
    Help Desk or higher can reveal a LAPS password. Secrets Auditor and Auditor cannot. Displaying a password starts **Automatically rotate after viewing (hours)** only if a LAPS Library Item is assigned.
  </Card>
</CardGroup>

## Best Practices

<Steps>
  <Step title="Reuse your Passcode settings">
    Import complexity settings from an existing Passcode Library Item if you have already tuned them, so LAPS and Passcode stay consistent.
  </Step>

  <Step title="Match your compliance requirements">
    Use **Automatically rotate after (days)** and **Automatically rotate after viewing (hours)** to balance convenience against how long a viewed password remains valid.
  </Step>

  <Step title="Review rotation activity">
    When a password fails to rotate, check the **Reason** field in [Unified Activity](/en/iru/platform-overview/unified-activity) or the device record **Activity** tab. Most failures state the cause directly.
  </Step>
</Steps>

## Troubleshooting

<AccordionGroup>
  <Accordion title="No admin account to import from 'ADE'.">
    **Possible causes:**

    * The ADE integration does not define a local administrator account

    **Solutions:**

    * In [Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment), confirm a local admin account is configured, then import again
  </Accordion>

  <Accordion title="Admin user from 'ADE' is already in the list.">
    **Possible causes:**

    * You already imported from that ADE integration
    * You added the same username manually

    **Solutions:**

    * Keep the existing row. Iru does not add a duplicate.
  </Accordion>

  <Accordion title="A password failed to rotate">
    When a password fails to rotate, check **Reason** in [Unified Activity](/en/iru/platform-overview/unified-activity) (`Reason: <cause>`) or the device record **Activity** tab (`<username>: <cause>`).

    **Possible causes:**

    * The Reason field names the cause, such as a locked keychain
    * The account is not a local administrator
    * Iru's stored current password does not match the device

    **Solutions:**

    * Confirm the account is an administrator. LAPS does not manage standard accounts
    * There is no automatic retry. The next attempt follows **Automatically rotate after (days)**
    * If the stored password is out of sync, [contact Iru Support](/en/iru/iru-support/access-to-iru-support)
  </Accordion>

  <Accordion title="Viewed the password, but it did not rotate">
    **Possible causes:**

    * No LAPS Library Item was assigned to the device at the time of viewing

    **Solutions:**

    * Assign a LAPS Library Item if you want **Automatically rotate after viewing (hours)** and **Automatically rotate after (days)** going forward
    * The view is still logged even when **Automatically rotate after viewing (hours)** does not start
  </Accordion>

  <Accordion title="Set Auto Admin Password is missing from device actions">
    **Possible causes:**

    * LAPS is assigned to this device, so the conflicting MDM command is hidden

    **Solutions:**

    * Expected when LAPS is assigned. Use **View local admin password** instead
    * Remove LAPS from the device's Blueprint only if you need the Set Auto Admin Password action
  </Accordion>

  <Accordion title="An admin account will not rotate">
    **Possible causes:**

    * The account is not an administrator
    * The account is not present on the device
    * The current password in the Library Item does not match the account on the device

    **Solutions:**

    * Confirm the account is a local administrator
    * Confirm the username matches the account on the Mac
    * Provide the current password on first assignment so Iru can take over the account
  </Accordion>
</AccordionGroup>

## Related Articles

<CardGroup cols={2}>
  <Card title="Library Overview" icon="list-check" href="/en/endpoint/library/library-items-profiles/library-overview">
    Curate, create, and manage Library Items and add them to Blueprints.
  </Card>

  <Card title="Iru Agent and MDM" icon="desktop" href="/en/endpoint/agent/iru-agent-and-mdm">
    LAPS is agent-based, so it works independently of Apple's MDM protocol.
  </Card>

  <Card title="Unified Activity" icon="timeline" href="/en/iru/platform-overview/unified-activity">
    Local admin password viewed and updated events appear in Unified Activity, not on the Activity Page.
  </Card>

  <Card title="Create User Accounts" icon="user-plus" href="/en/endpoint/blueprints/parameters/create-user-accounts">
    Create local administrator accounts for LAPS to rotate. LAPS does not create accounts.
  </Card>

  <Card title="Configure the Passcode Library Item" icon="lock" href="/en/endpoint/library/library-items-profiles/configure-the-passcode-library-item">
    Enforce passcode requirements, including settings you can import into LAPS.
  </Card>

  <Card title="Configure the Recovery Password Library Item" icon="key" href="/en/endpoint/library/library-items-profiles/configure-the-recovery-password-library-item">
    Configure recovery passwords on Mac computers with Apple silicon and Intel.
  </Card>

  <Card title="Set the Auto Admin Account Password" icon="user-shield" href="/en/endpoint/devices/device-actions/set-the-auto-admin-account-password">
    The MDM command LAPS replaces while it is assigned.
  </Card>

  <Card title="Configure Automated Device Enrollment" icon="apple" href="/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment">
    ADE integrations you can import admin accounts from.
  </Card>

  <Card title="Configure FileVault" icon="hard-drive" href="/en/endpoint/library/deployment-guides/apple/configure-filevault">
    FileVault encryption and recovery keys on Mac computers.
  </Card>
</CardGroup>
