How to Implement Windows LAPS in Microsoft Intune

Answer Correct answer: B — Implement Windows LAPS by creating an Endpoint security Account protection policy in Microsoft Intune.

You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Intune to manage Windows 11 devices. You need to implement Windows Local Administrator Password Solution (Windows LAPS). What should you configure?

  1. a configuration profile
  2. an account protection policy Correct Answer
  3. an app protection policy
  4. a device compliance policy

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests whether you know the Intune-native Windows LAPS policy is created under Endpoint security > Account protection; the trap is choosing a configuration profile because LAPS settings also surface in the settings catalog.

Windows LAPS in Microsoft Intune is deployed through an Endpoint security Account protection policy, not a device configuration profile or compliance policy. This page confirms why option B is the intended MD-102 answer and explains each alternative.

Choosing A (a configuration profile), because many Windows settings are delivered through device configuration profiles or the settings catalog, but the dedicated Windows LAPS policy is created under Endpoint security Account protection.

Community Discussion (7 comments)

Krayzr 👍 7
To implement Windows Local Administrator Password Solution (Windows LAPS) with Microsoft Intune, you should configure an account protection policy. This policy can enforce password requirements for local admin accounts, back up a local admin account from devices to your Active Directory (AD) or Microsoft Entra, and schedule rotation of those account passwords to help keep them safe. https://learn.microsoft.com/en-us/mem/intune/protect/windows-laps-overview
Knight_Of_Peace 👍 1 Selected: B
Technically, LAPS can be setup from Account Protection or from Device Configuration, but according to the following link, it created from Account Protection. https://learn.microsoft.com/en-us/mem/intune/protect/windows-laps-policy#:~:text=Sign%20in%20to%20the%20Microsoft%20Intune%20admin%20center%20and%20go%20to%20Endpoint%20security%20%3E%20Account%20protection%2C%20and%20then%20select%20Create%20Policy.
bigreg 👍 2 Selected: B
Correct
Rezaee 👍 1 Selected: A
The correct answer is A. a configuration profile.
ergacharsk 👍 1 Selected: B
agree with the given answer
MR_Eliot 👍 1
Correct
AdrianoM 👍 3 Selected: B
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Microsoft Intune, Windows LAPS is deployed by creating a policy at Endpoint security > Account protection > Create policy > Windows LAPS. This dedicated policy backs up the local administrator password to Microsoft Entra ID or on-premises Active Directory, enforces password complexity and length, and schedules automatic password rotation. Because the question asks how to implement Windows LAPS in Intune, the account protection policy is the correct vehicle. The Intune Suite licensing adds advanced endpoint management features, but it does not change the location of the LAPS policy. Option B matches Microsoft's documented Windows LAPS policy workflow.

Why the Other Options Are Wrong

A configuration profile (A) is the generic Intune container for device settings, and although some LAPS settings appear in the settings catalog, the exam expects the purpose-built LAPS policy under Account protection. An app protection policy (C) governs app-level data protection on mobile platforms, not local administrator credentials on Windows 11. A device compliance policy (D) evaluates conditions like BitLocker or Secure Boot and reports compliance state; it cannot generate, back up, or rotate a local admin password. None of those options deliver the LAPS backup-to-directory behavior required by the scenario.

Community Comment Notes

Krayzr summarized the policy's purpose accurately, noting it can enforce password requirements, back up a local admin account to AD or Entra, and rotate passwords. Knight_Of_Peace acknowledged nuance, writing that "LAPS can be setup from Account Protection or from Device Configuration" before concluding the Microsoft documentation points to Account protection. Rezaee dissented with "The correct answer is A. a configuration profile," which reflects the common settings-catalog confusion rather than the documented Intune LAPS policy path. Most voters landed on B, consistent with the official guidance.

Official Reference

Exam Strategy

When an MD-102 question says "implement Windows LAPS" in Intune, scan for Endpoint security > Account protection as the answer location. Resist the urge to pick a configuration profile just because LAPS settings also exist in the settings catalog; the dedicated LAPS policy is what the exam expects. Remember that LAPS needs Entra ID or AD as the password backup directory.

Frequently Asked Questions

Why is an Intune configuration profile not the primary choice for Windows LAPS?

Although LAPS settings can be reached through the settings catalog, Intune's dedicated Windows LAPS policy is created under Endpoint security > Account protection, which is what MD-102 expects.

What directory does Windows LAPS use to store the local admin password?

Windows LAPS backs up the password to Microsoft Entra ID or to Windows Server Active Directory, so the tenant needs one of those directory services available.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide