How to Implement Windows LAPS in Microsoft Intune
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Intune to manage Windows 11 devices. You need to implement Windows Local Administrator Password Solution (Windows LAPS). What should you configure?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests whether you know the Intune-native Windows LAPS policy is created under Endpoint security > Account protection; the trap is choosing a configuration profile because LAPS settings also surface in the settings catalog.
Windows LAPS in Microsoft Intune is deployed through an Endpoint security Account protection policy, not a device configuration profile or compliance policy. This page confirms why option B is the intended MD-102 answer and explains each alternative.
Choosing A (a configuration profile), because many Windows settings are delivered through device configuration profiles or the settings catalog, but the dedicated Windows LAPS policy is created under Endpoint security Account protection.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Microsoft Intune, Windows LAPS is deployed by creating a policy at Endpoint security > Account protection > Create policy > Windows LAPS. This dedicated policy backs up the local administrator password to Microsoft Entra ID or on-premises Active Directory, enforces password complexity and length, and schedules automatic password rotation. Because the question asks how to implement Windows LAPS in Intune, the account protection policy is the correct vehicle. The Intune Suite licensing adds advanced endpoint management features, but it does not change the location of the LAPS policy. Option B matches Microsoft's documented Windows LAPS policy workflow.Why the Other Options Are Wrong
A configuration profile (A) is the generic Intune container for device settings, and although some LAPS settings appear in the settings catalog, the exam expects the purpose-built LAPS policy under Account protection. An app protection policy (C) governs app-level data protection on mobile platforms, not local administrator credentials on Windows 11. A device compliance policy (D) evaluates conditions like BitLocker or Secure Boot and reports compliance state; it cannot generate, back up, or rotate a local admin password. None of those options deliver the LAPS backup-to-directory behavior required by the scenario.Community Comment Notes
Krayzr summarized the policy's purpose accurately, noting it can enforce password requirements, back up a local admin account to AD or Entra, and rotate passwords. Knight_Of_Peace acknowledged nuance, writing that "LAPS can be setup from Account Protection or from Device Configuration" before concluding the Microsoft documentation points to Account protection. Rezaee dissented with "The correct answer is A. a configuration profile," which reflects the common settings-catalog confusion rather than the documented Intune LAPS policy path. Most voters landed on B, consistent with the official guidance.Official Reference
Exam Strategy
When an MD-102 question says "implement Windows LAPS" in Intune, scan for Endpoint security > Account protection as the answer location. Resist the urge to pick a configuration profile just because LAPS settings also exist in the settings catalog; the dedicated LAPS policy is what the exam expects. Remember that LAPS needs Entra ID or AD as the password backup directory.
Frequently Asked Questions
Why is an Intune configuration profile not the primary choice for Windows LAPS?
Although LAPS settings can be reached through the settings catalog, Intune's dedicated Windows LAPS policy is created under Endpoint security > Account protection, which is what MD-102 expects.
What directory does Windows LAPS use to store the local admin password?
Windows LAPS backs up the password to Microsoft Entra ID or to Windows Server Active Directory, so the tenant needs one of those directory services available.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →