A thread · 4 notes · Script Library
Local admin, done right.
One-off admin accounts, LAPS-managed accounts, password rotation and who's in the Administrators group.
- 1
Create a Local Administrator Account with PowerShell
A one-off local admin account done properly, with a hidden password prompt, a language-proof group lookup, and an expiry date for the temporary ones.
- 2
Create a Dedicated Local Admin Account for Windows LAPS to Manage
Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
- 3
Rotate Local Admin Passwords Across the Fleet with Windows LAPS and ConfigMgr
Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
- 4
Adding Domain Groups to Local Administrators on Remote PCs with PowerShell
Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.