Windows LAPS Password Retrieval
This guide shows support engineers and device administrators how to retrieve a Windows LAPS managed local administrator password (via Entra ID or Intune) and use it to complete a UAC elevation on the target device.
Role Requirements
Procedure Scope: Administrators
Required Group Membership: Admin.Device
Handbook Reference
Package: Device Security
Domain: N/A
Modifies: N/A
![]()
Important notes:
- Windows‑only: LAPS is available only for Windows OS devices.
- Per‑device uniqueness: Each device targeted by your Windows LAPS policy has its own unique local administrator password that applies only to that device. Using a captured password from one machine on any other device will fail with authentication errors.
- Handling & hygiene: Viewing passwords may be audited. Use credentials only for authorized tasks, avoid persisting them in tickets or chats, and respect your rotation/expiration settings.
Accessing Local Admin Password via Entra ID
-
Navigate to the Devices - Entra ID portal. We will initially be displayed with the Overview page; we will select the Local administrator password recovery tab to view a list of machines that have active LAPS configuration.
Note: LAPS configuration via Intune is only applicable to Windows OS machines, if you attempt to leverage this process on a device that is running macOS or Linux OS then this information is not applicable. - From the returned list of machines that have an active Local Admin Password configured, locate and select the Show local administrator password action for the desired machine you are attempting to fulfill the UAC for. Once selected a Local administrator password pop-out will be displayed, here you will want to document the Account name of Administrator and leverage the Copy to clipboard action to copy the configured local administrator password.
Note: The local administrator password that is displayed for the desired machine is only applicable to that device; every machine that has LAPS enabled via Intune will have a unique password assigned to it that cannot be leveraged on a device that is not associated with the original device entry.
- The Account name entry is the Username that will be leveraged within the UAC prompt, and the Local administrator password is the password that will be leveraged in the same prompt widow. Fulfilling and transferring this information to the machine will be up to your discretion; and the methods of fulfilling UAC can either be hands-on-keyboard for on-site users or RMM for remote users if the leveraged software supports displaying these UAC windows.
Accessing Local Admin Password via Intune
-
Navigate to the Devices - Intune portal. From the returned list of Intune joined machines, locate and select the desired machine you are attempting to fulfill the UAC for.
Note: LAPS configuration via Intune is only applicable to Windows OS machines, if you attempt to leverage this process on a device that is running macOS or Linux OS then this information is not applicable.
- We will initially be displayed with the Overview page; we will select the Local administrator password tab to view the active local administrator password that is configured on the machine.
- Locate and select the Show local administrator password action. Once selected a Local administrator password pop-out will be displayed, here you will want to document the Account name of Administrator and leverage the Copy to clipboard action to copy the configured local administrator password.

- The Account name entry is the Username that will be leveraged within the UAC prompt, and the Local administrator password is the password that will be leveraged in the same prompt widow. Fulfilling and transferring this information to the machine will be up to your discretion; and the methods of fulfilling UAC can either be hands-on-keyboard for on-site users or RMM for remote users if the leveraged software supports displaying these UAC windows.
Fulfilling UAC Prompt Using Captured Credential
- For the machine that was experiencing the UAC prompt due to installing new software, attempting to launch a CMD or PowerShell as Admin, etc. We will leverage the Administrator Account Name and the copied Local administrator password that were captured from the previous steps.
Note: For the Administrator username, you will be required to use the .\ to leverage the local administrator account that is configured on the device. Failure to include the .\ will result in a ‘The username or password is incorrect’ prompt because the lack of local directory indication means that the local administrator account is not being targeted.
- If ./Administrator and the configured Local Administrator Password that was previously captured are supplied correctly, the user will be granted access to whatever initially prompted the UAC.

Need Assistance?
Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? Inquire about arranging a consultation to explore optimizing your Azure environment for painless management.
