Migrated from KelvinTegelaar/CIPP#6412, opened by shamsabacusgroup on 2026-07-22
Please confirm:
Problem Statement
Many MSPs rely on Windows LAPS (Local Administrator Password Solution) to secure local administrator accounts on managed endpoints. While CIPP provides visibility and monitoring for many Microsoft 365 security configurations, there is currently no straightforward way to identify tenants where Windows LAPS is not enabled, improperly configured, or has fallen out of compliance.
We would like the ability to automatically detect and report on Windows LAPS configuration status across managed tenants and receive alerts when issues are identified.
Examples of non-compliance may include:
Windows LAPS not configured through Intune policies.
Required LAPS settings missing or disabled.
- Backup Directory
- Password Age Days
- Administrator Account Name
- Password Complexity
- Password Length
- Automatic Account Management
LAPS policy assignments removed or modified.
Devices failing to receive or apply LAPS configuration.
Drift from a defined LAPS security standard.
The feature could evaluate whether a compliant LAPS policy exists and alert when required settings are missing or differ from a defined standard.
Benefits for MSPs
Improving endpoint security visibility across all managed tenants.
Reducing the need for manual audits of Intune and LAPS configurations.
Providing proactive notification when a tenant becomes non-compliant.
Supporting security best practices and cyber insurance requirements.
Helping service desks and security teams quickly identify customers requiring remediation.
Allowing MSPs to include LAPS compliance in their standard security monitoring processes.
Potential use cases include:
Alert when a tenant has no Windows LAPS policy configured.
Alert when a required LAPS policy is disabled.
Include LAPS status within Standards and Drift reporting.
Value or Importance
Windows LAPS is a core security control recommended by Microsoft and widely adopted by MSPs to protect local administrator accounts.
Without centralized monitoring, configuration issues may go unnoticed until a security review or incident occurs. As MSPs scale across hundreds of tenants, manually validating LAPS compliance becomes increasingly difficult.
Adding LAPS compliance monitoring would enable proactive detection of security drift, improve customer security posture, and align with CIPP's existing goals of standardization, monitoring, and automated remediation across multiple tenants.
Ideally this feature could integrate with:
Standards
Drift detection
Alerting
Tenant reports
Secure Score-related monitoring
PowerShell Commands (Optional)
No response
Please confirm:
Problem Statement
Many MSPs rely on Windows LAPS (Local Administrator Password Solution) to secure local administrator accounts on managed endpoints. While CIPP provides visibility and monitoring for many Microsoft 365 security configurations, there is currently no straightforward way to identify tenants where Windows LAPS is not enabled, improperly configured, or has fallen out of compliance.
We would like the ability to automatically detect and report on Windows LAPS configuration status across managed tenants and receive alerts when issues are identified.
Examples of non-compliance may include:
Windows LAPS not configured through Intune policies.
Required LAPS settings missing or disabled.
LAPS policy assignments removed or modified.
Devices failing to receive or apply LAPS configuration.
Drift from a defined LAPS security standard.
The feature could evaluate whether a compliant LAPS policy exists and alert when required settings are missing or differ from a defined standard.
Benefits for MSPs
Improving endpoint security visibility across all managed tenants.
Reducing the need for manual audits of Intune and LAPS configurations.
Providing proactive notification when a tenant becomes non-compliant.
Supporting security best practices and cyber insurance requirements.
Helping service desks and security teams quickly identify customers requiring remediation.
Allowing MSPs to include LAPS compliance in their standard security monitoring processes.
Potential use cases include:
Alert when a tenant has no Windows LAPS policy configured.
Alert when a required LAPS policy is disabled.
Include LAPS status within Standards and Drift reporting.
Value or Importance
Windows LAPS is a core security control recommended by Microsoft and widely adopted by MSPs to protect local administrator accounts.
Without centralized monitoring, configuration issues may go unnoticed until a security review or incident occurs. As MSPs scale across hundreds of tenants, manually validating LAPS compliance becomes increasingly difficult.
Adding LAPS compliance monitoring would enable proactive detection of security drift, improve customer security posture, and align with CIPP's existing goals of standardization, monitoring, and automated remediation across multiple tenants.
Ideally this feature could integrate with:
Standards
Drift detection
Alerting
Tenant reports
Secure Score-related monitoring
PowerShell Commands (Optional)
No response