Post-authentication actions
Verified with Windows 11 25H2 — updated on July 10, 2026
Supported on: At least Microsoft Windows 10 or later
Path in the GPO console
Computer Configuration\Administrative Templates\System\LAPS Description
This policy configures post-authentication actions which will be executed after detecting an authentication by the managed account. Grace period: specifies the amount of time (in hours) to wait after an authentication before executing the specified post-authentication actions. If this setting is enabled and greater than zero, the specified post-authentication actions will be executed upon expiration of the grace period. If this setting is disabled or not configured, the specified post-authentication actions will be executed after a default 24 hour grace period. If this setting is equal to zero, no post-authentication actions will be executed. Actions: specifies the actions to take upon expiration of the grace period. Reset password: upon expiration of the grace period, the managed account password is reset. Reset the password and logoff the managed account: upon expiration of the grace period, the managed account password is reset and any interactive logon sessions using the managed account are logged off. Reset the password and reboot: upon expiration of the grace period, the managed account password is reset and the managed device is rebooted. Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated. (NOTE: after any interactive logon sessions are terminated there may still be other authenticated sessions in use by the managed account. The only robust way to ensure that the previous password is longer in use is to reboot the device.) If this setting is disabled or not configured, post-authentication actions will default to "Reset the password and logoff the managed account". Note: the DSRM account on domain controllers cannot be configured for post-authentication actions. This policy has no effect on domain controllers and will be ignored even if configured for a DC. See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
Registry
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Post-authentication actions
; State: Enabled
; Supported on: At least Microsoft Windows 10 or later
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS]
"PostAuthenticationResetDelay"=dword:00000018
"PostAuthenticationActions"=dword:00000003 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Post-authentication actions
# State: Enabled
# Supported on: At least Microsoft Windows 10 or later
$path = 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PostAuthenticationResetDelay' -Value 24 -Type DWord
Set-ItemProperty -Path $path -Name 'PostAuthenticationActions' -Value 3 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Post-authentication actions
# State: Enabled
# Supported on: At least Microsoft Windows 10 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS' -Name 'PostAuthenticationResetDelay' -Expected 24 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS' -Name 'PostAuthenticationActions' -Expected 3 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Post-authentication actions
# State: Enabled
# Supported on: At least Microsoft Windows 10 or later
$path = 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PostAuthenticationResetDelay' -Value 24 -Type DWord
Set-ItemProperty -Path $path -Name 'PostAuthenticationActions' -Value 3 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Post-authentication actions
# State: Enabled
# Supported on: At least Microsoft Windows 10 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Post-authentication actions
# State: Enabled
# Supported on: At least Microsoft Windows 10 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS' -Name 'PostAuthenticationResetDelay' -Expected 24 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS' -Name 'PostAuthenticationActions' -Expected 3 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Post-authentication actions
# State: Enabled
# Supported on: At least Microsoft Windows 10 or later
$path = 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PostAuthenticationResetDelay' -Value 24 -Type DWord
Set-ItemProperty -Path $path -Name 'PostAuthenticationActions' -Value 3 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.