Skip to content

[Feature Request]: Windows LAPS Compliance Monitoring and Alerting #41

Description

@KelvinTegelaar

Migrated from KelvinTegelaar/CIPP#6412, opened by shamsabacusgroup on 2026-07-22

Please confirm:

  • I have searched existing feature requests (open and closed) and found no duplicates.
  • **me or my organization is currently an active sponsor of the product at the $99,- level.

Problem Statement

Many MSPs rely on Windows LAPS (Local Administrator Password Solution) to secure local administrator accounts on managed endpoints. While CIPP provides visibility and monitoring for many Microsoft 365 security configurations, there is currently no straightforward way to identify tenants where Windows LAPS is not enabled, improperly configured, or has fallen out of compliance.
We would like the ability to automatically detect and report on Windows LAPS configuration status across managed tenants and receive alerts when issues are identified.
Examples of non-compliance may include:

Windows LAPS not configured through Intune policies.
Required LAPS settings missing or disabled.

  • Backup Directory
  • Password Age Days
  • Administrator Account Name
  • Password Complexity
  • Password Length
  • Automatic Account Management

LAPS policy assignments removed or modified.
Devices failing to receive or apply LAPS configuration.
Drift from a defined LAPS security standard.

The feature could evaluate whether a compliant LAPS policy exists and alert when required settings are missing or differ from a defined standard.

Benefits for MSPs

Improving endpoint security visibility across all managed tenants.
Reducing the need for manual audits of Intune and LAPS configurations.
Providing proactive notification when a tenant becomes non-compliant.
Supporting security best practices and cyber insurance requirements.
Helping service desks and security teams quickly identify customers requiring remediation.
Allowing MSPs to include LAPS compliance in their standard security monitoring processes.

Potential use cases include:

Alert when a tenant has no Windows LAPS policy configured.
Alert when a required LAPS policy is disabled.
Include LAPS status within Standards and Drift reporting.

Value or Importance

Windows LAPS is a core security control recommended by Microsoft and widely adopted by MSPs to protect local administrator accounts.
Without centralized monitoring, configuration issues may go unnoticed until a security review or incident occurs. As MSPs scale across hundreds of tenants, manually validating LAPS compliance becomes increasingly difficult.
Adding LAPS compliance monitoring would enable proactive detection of security drift, improve customer security posture, and align with CIPP's existing goals of standardization, monitoring, and automated remediation across multiple tenants.
Ideally this feature could integrate with:

Standards
Drift detection
Alerting
Tenant reports
Secure Score-related monitoring

PowerShell Commands (Optional)

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions