Set the DPAPI backup keys rotation period
Verified with Windows 11 25H2 — updated on July 10, 2026
Supported on: At least Windows Server 2016
Path in the GPO console
Computer Configuration\Administrative Templates\System\DPAPI Description
This policy setting specifies the DPAPI backup keys rotation period. You can use this setting to override the default value of 90 days. Set 0 to disable the DPAPI backup keys rotation. If you enable this policy setting, set the number of days that the system waits before generating a new DPAPI backup key. If you disable or do not configure this policy setting, the default value of 90 days is used.
Registry
Software\Policies\Microsoft\Windows\DPAPI Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Set the DPAPI backup keys rotation period
; State: Enabled
; Supported on: At least Windows Server 2016
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DPAPI]
"DomainBackupKeyRotationPeriod"=dword:0000005a More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Set the DPAPI backup keys rotation period
# State: Enabled
# Supported on: At least Windows Server 2016
$path = 'HKLM:\Software\Policies\Microsoft\Windows\DPAPI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DomainBackupKeyRotationPeriod' -Value 90 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Set the DPAPI backup keys rotation period
# State: Enabled
# Supported on: At least Windows Server 2016
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\DPAPI' -Name 'DomainBackupKeyRotationPeriod' -Expected 90 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Set the DPAPI backup keys rotation period
# State: Enabled
# Supported on: At least Windows Server 2016
$path = 'HKLM:\Software\Policies\Microsoft\Windows\DPAPI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DomainBackupKeyRotationPeriod' -Value 90 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Set the DPAPI backup keys rotation period
# State: Enabled
# Supported on: At least Windows Server 2016
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Set the DPAPI backup keys rotation period
# State: Enabled
# Supported on: At least Windows Server 2016
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\DPAPI' -Name 'DomainBackupKeyRotationPeriod' -Expected 90 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Set the DPAPI backup keys rotation period
# State: Enabled
# Supported on: At least Windows Server 2016
$path = 'HKLM:\Software\Policies\Microsoft\Windows\DPAPI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DomainBackupKeyRotationPeriod' -Value 90 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.