Enable local admin password management
Verified with Microsoft LAPS (legacy) 6.2 — updated on September 15, 2026 Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
Deprecated: this setting belongs to the legacy Microsoft LAPS, replaced by Windows LAPS built into Windows. Windows LAPS equivalent: Configure password backup directory.
Path in the GPO console
Computer Configuration\Administrative Templates\LAPS Registry
Software\Policies\Microsoft Services\AdmPwd - Value name:
-
AdmPwdEnabled
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_Enabled Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Description
Enables management of password for local administrator account If you enable this setting, local administrator password is managed If you disable or not configure this setting, local administrator password is NOT managed
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Enable local admin password management
; State: Enabled
; Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft Services\AdmPwd]
"AdmPwdEnabled"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Enable local admin password management
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AdmPwdEnabled' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_Enabled
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Enable local admin password management
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft Services\AdmPwd' -Name 'AdmPwdEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Enable local admin password management
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AdmPwdEnabled' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Enable local admin password management
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Enable local admin password management
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft Services\AdmPwd' -Name 'AdmPwdEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Enable local admin password management
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AdmPwdEnabled' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.