How to generate and export LAPS information in reports using ADManager Plus

How to generate and export LAPS information in reports using ADManager Plus

Objective 

This article explains how to retrieve and export Local Administrator Password Solution (LAPS) information using ADManager Plus. LAPS helps you securely manage the local administrator passwords of domain-joined computers. By configuring ADManager Plus to access this information, you can generate reports for auditing, enhance visibility, and maintain better control over local account credentials across your environment.

Prerequisites   

  • LAPS must be deployed and configured in your Active Directory (AD) environment.

  • ADManager Plus must have permission to read LAPS attributes (ms-Mcs-AdmPwd and ms-Mcs-AdmPwdExpirationTime) from AD.

  • If the primary domain controller is running Windows Server 2022 or above, please configure it in ADManager Plus under Directory/Application Settings.

  • LAPS attributes must be extended to the schema and applied to computer objects.

  • Please make sure remote PowerShell is enabled from the server where ADManager Plus is installed and the domain controller is configured.

  • The technician configured in ADManager Plus should have access to view the LAPS information.

Notes

Note: To provide the technician with access, navigate to Delegation > Help Desk Delegation > Help Desk Technicians, locate the technician, click Edit > Show Advanced, and enable Display LAPS information in reports.

Steps to follow 

  1. For legacy Microsoft LAPS

    1. Log in to ADManager Plus.

    2. Navigate to Reports > Computer Reports > General Reports > Workstation Computers.

    3. Select the domain and OU from which you want to retrieve the information.

    4. Click Generate.

    5. Once the report is generated, click Add or Remove Column, move Local Administrator Password(LAPS) from Available Attributes to Selected Attributes, and click OK.

    6. Click the Export As option to download the report in your preferred format (CSVDE, CSV, PDF, XLSX, or HTML).

  2. For Windows LAPS

    1. Log in to ADManager Plus.

    2. Navigate to the AD Explorer option in the top-right corner of the dashboard.

    3. Browse to the location of the computer for which you want to view the data.

    4. Under the Properties tab, in the LAPS Details section, view the local administrator password information.

    5. Click the Export As option to download the report in your preferred format (CSV, PDF, XLSX, or HTML).

Notes

Note: 

  • You can also schedule this report for automated delivery via email under Reports > Schedule Reports.

  • Once the report runs, it will display the LAPS password and its expiration time for each computer, provided the necessary permissions are in place.

Tips   

  • Always ensure that only authorized users have access to reports containing LAPS passwords.

  • For added security, restrict report export permissions to specific technician roles.

  • Schedule regular LAPS reports to stay informed of password expiration timelines.

                  New to ADSelfService Plus?

                    • Related Articles

                    • How to display and export LAPS Information in reports

                      Steps to allow technicians to export the LAPS password in reports: 1. Log in to ADManager Plus. 2. Navigate to the Admin tab. 3. Under General Settings, click Security and Privacy. 4. In the Privacy Settings tab, check the Allow technicians to export ...
                    • Unable to view LAPS password in ADManager Plus

                      Issue description The LAPS password column in the Workstation Computers report of ADManager Plus is empty. Possible causes Incorrect LAPS configuration: LAPS might not be correctly configured or deployed. Permission issues: The user account used by ...
                    • Unable to generate any data in the scheduled reports using ADManager Plus

                      Issue description Scheduled reports in ADManager Plus are essential for automating the delivery of critical information related to Active Directory (AD) objects, such as user accounts, group memberships, and compliance status. They ensure that ...
                    • How do I generate a list of members in a specific distribution group using ADManager Plus?

                      Objective Administrators often need to audit or review the membership of specific distribution groups for communication tracking, access control, or compliance purposes. ADManager Plus allows you to generate targeted reports that list selected ...
                    • Microsoft 365 license management using ADManager Plus

                      This article will explain how you can assign and revoke Microsoft 365 licenses using ADManager Plus. With ADManager Plus, you can: Assign Microsoft 365 licenses while creating users. Modify Microsoft 365 licenses for existing users. Remove Microsoft ...