{"id":1814,"date":"2015-05-18T15:06:18","date_gmt":"2015-05-18T13:06:18","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=1814"},"modified":"2015-05-18T15:06:18","modified_gmt":"2015-05-18T13:06:18","slug":"microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/","title":{"rendered":"Microsoft LAPS: Managing local administrator passwords"},"content":{"rendered":"<div>\n<div>\n<div>\n<h1>Problem statement<\/h1>\n<p>Following the compromise of one machine, attackers will seek to leverage other machines to escalate their privileges or gain access to the information they desire.<\/p>\n<p>Within Windows domains, a bounce technique involves exploiting the local administrator account, whose password is often the same across machines. This password can be easily obtained if it is deployed via GPO (see...). <a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-1812\">CVE-2014-1812<\/a> \/ <a href=\"https:\/\/technet.microsoft.com\/library\/security\/ms14-025\">MS14-025<\/a> \/ <a href=\"https:\/\/support.microsoft.com\/en-us\/kb\/2962486\">KB2962486<\/a>), otherwise attackers can obtain the hash and use it directly to authenticate on other machines (Pass-The-Hash technique).<\/p>\n<p>Our experience from penetration tests conducted by Intrinsec at our clients&#039; sites shows that this redirection technique is very often feasible. We continue to discover passwords in Group Policy Objects (GPOs): although this functionality has been removed by Microsoft, the policy must be manually cleaned to properly remove the password.<\/p>\n<p>To address this widespread problem, Microsoft released the Local Administrator Password Solution (LAPS) tool on May 1, 2015. <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/3062591\">MSA3062591<\/a> \/ <a href=\"https:\/\/support.microsoft.com\/en-us\/kb\/3062591\/\">KB3062591<\/a>.<\/p>\n<p>This solution is free, is based on the existing infrastructure (Active Directory domain) and allows the administration of workstations (e.g. administrators or support).<\/p>\n<p>&nbsp;<\/p>\n<h1>Deployment tips<\/h1>\n<p>For general deployment instructions, we recommend that you follow the guide provided by Microsoft, the file of which is called &quot;LAPS_OperationsGuide.docx&quot;.<\/p>\n<p>The machines on which LAPS is deployed generate a random password and store it in their machine account in the Active Directory database:<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-2.png\"><img decoding=\"async\" class=\"aligncenter size-medium wp-image-1818\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-2-300x132.png\" alt=\"LAPS (2)\" width=\"300\" height=\"132\" \/><\/a>It is therefore important to restrict access to the ms-Mcs-AdmPwd attribute, for example, to workstation administrators or support staff. Two PowerShell commands are available for this purpose:<\/p>\n<ul type=\"disc\">\n<li>Set-AdmPwdReadPasswordPermission: read access to the password<\/li>\n<li>Set-AdmPwdResetPasswordPermission: write access to reset it<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Note that if the &quot;extended rights&quot; permission is enabled on the OU for certain groups, which is not the default setting, these groups will also have access to passwords. This topic is discussed in the &quot;LAPS_OperationsGuide.docx&quot; installation guide, section 2.2.1.<\/p>\n<p>The PowerShell command `Find-AdmPwdExtendedRights` allows you to see the affected groups. Here is an example (intentionally vulnerable):<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-3.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1819\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-3-300x281.png\" alt=\"LAPS (3)\" width=\"300\" height=\"281\" \/><\/a><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-4.png\"><img decoding=\"async\" class=\"aligncenter wp-image-1820 size-full\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-4.png\" alt=\"LAPS (4)\" width=\"853\" height=\"72\" \/><\/a><\/p>\n<h1>From a pentester&#039;s point of view<\/h1>\n<p>NetSPI published an article to introduce LAPS and share a PowerShell script for recovering poorly protected passwords: <a href=\"https:\/\/blog.netspi.com\/running-laps-around-cleartext-passwords\/\">Running LAPS Around Cleartext Passwords<\/a>. The script automatically filters active machine accounts and indicates whether LAPS is used (presence of the expiration attribute) and the password if it is readable.<\/p>\n<p>It is possible to achieve a similar result with a simple LDAP client (here LDAP Browser) and a query:<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1821 size-full\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-5.png\" alt=\"LAPS (5)\" width=\"674\" height=\"268\" \/><\/a>Passwords from machines to AD are transmitted via LDAP with encryption and signature options enabled (source: <a href=\"https:\/\/code.msdn.microsoft.com\/windowsdesktop\/Solution-for-management-of-ae44e789\/sourcecode?fileId=131854&amp;pathId=606758226\">https:\/\/code.msdn.microsoft.com\/windowsdesktop\/Solution-for-management-of-ae44e789\/sourcecode?fileId=131854&amp;pathId=606758226<\/a>).<\/p>\n<p>LDAP connection to AD:<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1822\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-6-300x179.png\" alt=\"LAPS (6)\" width=\"300\" height=\"179\" \/><\/a>Sending the password for storage:<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1823\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-7-300x175.png\" alt=\"LAPS (7)\" width=\"300\" height=\"175\" \/><\/a><\/p>\n<h1>Examples<\/h1>\n<p>Initial configuration using PowerShell on Active Directory:<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1824 size-full\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-8.png\" alt=\"LAPS (8)\" width=\"953\" height=\"446\" \/><\/a><\/p>\n<ol type=\"1\">\n<li value=\"1\">List of available commands<\/li>\n<li>Updated AD schema for new attributes<\/li>\n<li>Verification of the restriction of the &quot;extended rights&quot; authorization\u00ab<\/li>\n<li>Allowing machines to save their password<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Be sure to configure the GPO correctly by enabling and configuring LAPS:<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1825\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-9-300x155.png\" alt=\"LAPS (9)\" width=\"300\" height=\"155\" \/><\/a><\/p>\n<p>Obtaining a password by an administrator using PowerShell and a thick client:<br \/>\n<a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1826 size-full\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-10.png\" alt=\"LAPS (10)\" width=\"844\" height=\"68\" \/><\/a><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1817\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2015\/05\/LAPS-1-300x231.png\" alt=\"LAPS (1)\" width=\"300\" height=\"231\" \/><\/a><\/p>\n<h1>Notes<\/h1>\n<ul>\n<li>Microsoft had initially published a simple PowerShell script in its <a href=\"https:\/\/support.microsoft.com\/en-us\/kb\/2962486\">KB2962486<\/a> to assign a different password to each machine. This solution has the disadvantage of storing the passwords in a text file, which is not recommended and does not allow sharing within an administration team.<\/li>\n<li>LAPS has existed since approximately 2012 under the name <a href=\"https:\/\/code.msdn.microsoft.com\/windowsdesktop\/Solution-for-management-of-ae44e789\">AdmPwd<\/a>. It has only just been officially released and supported by Microsoft.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p><em>\u2014 Cl\u00e9ment Notin<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Problem Statement: Following a breach of a machine, attackers will seek to rebound [\u2026]<\/p>","protected":false},"author":1,"featured_media":1835,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,19,22],"tags":[128,129,130,131,132,133,88],"class_list":["post-1814","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-conseil-ssi","category-soc-securite-operationnelle","category-veille-securite","tag-ad","tag-admin-local","tag-domaine","tag-laps","tag-ldap","tag-microsoft","tag-pentest"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Microsoft LAPS : gestion des mots de passe des administrateurs locaux - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft LAPS : gestion des mots de passe des administrateurs locaux\" \/>\n<meta property=\"og:description\" content=\"Pr\u00e9sentation du probl\u00e8me Suite \u00e0 une compromission d&rsquo;une machine, les attaquants vont chercher \u00e0 rebondir [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2015-05-18T13:06:18+00:00\" \/>\n<meta name=\"author\" content=\"Intrinsec\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Intrinsec\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/\"},\"author\":{\"name\":\"Intrinsec\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/ade590fbc7ad6f413727bae7cd3fb799\"},\"headline\":\"Microsoft LAPS : gestion des mots de passe des administrateurs locaux\",\"datePublished\":\"2015-05-18T13:06:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/\"},\"wordCount\":697,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"keywords\":[\"AD\",\"admin local\",\"domaine\",\"LAPS\",\"LDAP\",\"Microsoft\",\"pentest\"],\"articleSection\":[\"Conseil SSI\",\"SOC S\u00e9curit\u00e9 Op\u00e9rationnelle\",\"Veille S\u00e9curit\u00e9\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/\",\"name\":\"Microsoft LAPS : gestion des mots de passe des administrateurs locaux - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2015-05-18T13:06:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft LAPS : gestion des mots de passe des administrateurs locaux\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/ade590fbc7ad6f413727bae7cd3fb799\",\"name\":\"Intrinsec\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"caption\":\"Intrinsec\"},\"sameAs\":[\"https:\\\/\\\/www.intrinsec.com\"],\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/ufhtbqccsz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Microsoft LAPS: Managing Local Administrator Passwords - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft LAPS : gestion des mots de passe des administrateurs locaux","og_description":"Pr\u00e9sentation du probl\u00e8me Suite \u00e0 une compromission d&rsquo;une machine, les attaquants vont chercher \u00e0 rebondir [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/","og_site_name":"INTRINSEC","article_published_time":"2015-05-18T13:06:18+00:00","author":"Intrinsec","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Intrinsec","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/"},"author":{"name":"Intrinsec","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/ade590fbc7ad6f413727bae7cd3fb799"},"headline":"Microsoft LAPS : gestion des mots de passe des administrateurs locaux","datePublished":"2015-05-18T13:06:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/"},"wordCount":697,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#primaryimage"},"thumbnailUrl":"","keywords":["AD","admin local","domaine","LAPS","LDAP","Microsoft","pentest"],"articleSection":["Conseil SSI","SOC S\u00e9curit\u00e9 Op\u00e9rationnelle","Veille S\u00e9curit\u00e9"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/","url":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/","name":"Microsoft LAPS: Managing Local Administrator Passwords - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#primaryimage"},"thumbnailUrl":"","datePublished":"2015-05-18T13:06:18+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/microsoft-laps-gestion-des-mots-de-passe-des-administrateurs-locaux\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Microsoft LAPS : gestion des mots de passe des administrateurs locaux"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/ade590fbc7ad6f413727bae7cd3fb799","name":"Intrinsic","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","caption":"Intrinsec"},"sameAs":["https:\/\/www.intrinsec.com"],"url":"https:\/\/www.intrinsec.com\/en\/author\/ufhtbqccsz\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/1814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=1814"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/1814\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=1814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=1814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=1814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}