Skip to main content

What is LAPS for computers?

In this guide we will set up the Cloud LAPS feature that is part of the Privileged Access Management (PAM) offering for MSPs. Cloud LAPS allows you to create break-glass / emergency accounts on all customer workstations (including domain controllers), automatically rotate passwords for these accounts every 24 hours, and store the credentials in idemeum zero-knowledge cloud vault.
Idemeum cloud is end-to-end encrypted, meaning our team does not see the passwords of your customers.

Set up LAPS for computers

We are assuming you already have your MSP idemeum cloud tenant provisioned. If not, reach out to our support team for help.
1

Create idemeum child tenant

As a first step you need to create a child organization in your parent MSP tenant.
  • Login to MSP admin portal
  • Navigate to Tenants and create a child organization
More information about how to create a child organization.
2

Configure LAPS settings

In this step we will enable LAPS settings for child tenant organization.
  • Navigate to your child tenant admin portal
  • Access SettingsJIT access and the look for LAPS for computers section
  • Enable LAPS for local machines and domain controllers using the toggles
  • Specify the account name for idemeum to use
You can use any account name you like, i.e. emergency. You can use built in Administrator account as well. Please note, that if the account exists, idemeum will take over and will start rotating passwords. If account does not exist, idemeum will create it.
Lapsc
3

Grab installation command and deploy agents

Now you need to access the child organization, click Install new agent, grab the installation command for Windows or macOS and install idemeum agent.
More about how to install idemeum agent.
4

View LAPS credentials

Once the agents are successfully installed, and the devices show up in the Devices section, you can start viewing LAPS credentials.
Switch to the user portal of your child organization (at the top right of the screen) and you will see the list of devices. Click on the device and choose View LAPS credentialsLapskk
You can also view LAPS credentials in the idemeum mobile app. Switch to the customer tenant you create, search for the device, and click on ...