ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Local User GPO - change?

    Scheduled Pinned Locked Moved IT Discussion
    25 Posts 6 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bbigfordB
      bbigford
      last edited by

      LAPS looks like garbage, you can't do bulk....

      0_1460141654554_LAPS.png

      1 Reply Last reply Reply Quote 0
      • IRJI
        IRJ
        last edited by

        This is how I do it.

        https://drive.google.com/open?id=0B-Zj7y7G1-C_aGFCeFI1Vzk4Zzh1eHN3ZDY3Rkg5YXVscDg0

        I am having trouble uploading that image for some reason on ML. If someone could upload it for me, that would be great.

        bbigfordB 2 Replies Last reply Reply Quote 2
        • bbigfordB
          bbigford @IRJ
          last edited by

          @IRJ 0_1460142052514_PW change.jpg

          1 Reply Last reply Reply Quote 3
          • wirestyle22W
            wirestyle22
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • wirestyle22W
              wirestyle22
              last edited by

              Beat me to it 😄

              1 Reply Last reply Reply Quote 1
              • bbigfordB
                bbigford @IRJ
                last edited by

                @IRJ said:

                This is how I do it.

                https://drive.google.com/open?id=0B-Zj7y7G1-C_aGFCeFI1Vzk4Zzh1eHN3ZDY3Rkg5YXVscDg0

                I am having trouble uploading that image for some reason on ML. If someone could upload it for me, that would be great.

                Good work around I guess. So you schedule it to redeploy then? We add lots of servers to our environment regularly, so a persistent change is necessary to always make sure a server is changing the local admin, in case it is needed.

                IRJI 2 Replies Last reply Reply Quote 0
                • IRJI
                  IRJ @bbigford
                  last edited by

                  @BBigford said:

                  @IRJ said:

                  This is how I do it.

                  https://drive.google.com/open?id=0B-Zj7y7G1-C_aGFCeFI1Vzk4Zzh1eHN3ZDY3Rkg5YXVscDg0

                  I am having trouble uploading that image for some reason on ML. If someone could upload it for me, that would be great.

                  Good work around I guess. So you schedule it to redeploy then? We add lots of servers to our environment regularly, so a persistent change is necessary to always make sure a server is changing the local admin, in case it is needed.

                  Yeah, but also update your server and desktop images with the latest passwords to make things easier.

                  1 Reply Last reply Reply Quote 0
                  • IRJI
                    IRJ @bbigford
                    last edited by

                    @BBigford said:

                    @IRJ said:

                    This is how I do it.

                    https://drive.google.com/open?id=0B-Zj7y7G1-C_aGFCeFI1Vzk4Zzh1eHN3ZDY3Rkg5YXVscDg0

                    I am having trouble uploading that image for some reason on ML. If someone could upload it for me, that would be great.

                    Good work around I guess. So you schedule it to redeploy then? We add lots of servers to our environment regularly, so a persistent change is necessary to always make sure a server is changing the local admin, in case it is needed.

                    You could do it weekly, daily, or even hourly. The script has hardly any network impact.

                    1 Reply Last reply Reply Quote 1
                    • IRJI
                      IRJ
                      last edited by

                      P.S.

                      It is good practice to rename your local Administrator accounts to something other than Administrator. I do that with Group Policy then set the password for the updated account name once it is changed by Group Policy.

                      1 Reply Last reply Reply Quote 0
                      • wrx7mW
                        wrx7m
                        last edited by

                        I ran into this problem a few months ago, though some time after an upgrade of the AD schema from 47 to 69.

                        I solved it by using a bat file that runs as a startup script right after an MDT deployment.

                        net user "My Admin" PasswordGoesHere /add /passwordreq:yes /fullname:"My Admin"
                        net localgroup Administrators "My Admin" /add

                        After the new PC is then moved to its final OU, LAPS is installed and a new random password is applied.

                        bbigfordB 1 Reply Last reply Reply Quote 0
                        • bbigfordB
                          bbigford @wrx7m
                          last edited by

                          @wrx7m said:

                          I ran into this problem a few months ago, though some time after an upgrade of the AD schema from 47 to 69.

                          I solved it by using a bat file that runs as a startup script right after an MDT deployment.

                          net user "My Admin" PasswordGoesHere /add /passwordreq:yes /fullname:"My Admin"
                          net localgroup Administrators "My Admin" /add

                          After the new PC is then moved to its final OU, LAPS is installed and a new random password is applied.

                          Hypothetically, what if you had to run LAPS against 100 servers? Growing by 10 servers every month and you don't build them all, so you don't know if the passwords are all getting set locally with the right password ... Would you still feel that is the best tool since you can't run LAPS against groups of servers like an OU?

                          wrx7mW 1 Reply Last reply Reply Quote 0
                          • wrx7mW
                            wrx7m @bbigford
                            last edited by

                            @BBigford Laps won't let you set the password. It assigns random ones that you can access the plain text version of via AD.

                            bbigfordB 1 Reply Last reply Reply Quote 0
                            • bbigfordB
                              bbigford @wrx7m
                              last edited by

                              @wrx7m said:

                              @BBigford Laps won't let you set the password. It assigns random ones that you can access the plain text version of via AD.

                              Well that's disappointing. Sounds like a pretty useless program. You can only do random ones, and one at a time.

                              wrx7mW 1 Reply Last reply Reply Quote 1
                              • wrx7mW
                                wrx7m @bbigford
                                last edited by wrx7m

                                @BBigford It does everything automatically, via GPO, not really one at a time. LAPS prevents each local admin from having the same password. Obviously, if you want everything to be the same then you wouldn't want to use it.

                                EDIT: You can still use the bat file (mentioned above) if you want to create a specific user with a specific password and assign it to the local admins group. Keep in mind that it is plain text, as was the method you were previously using.

                                1 Reply Last reply Reply Quote 0
                                • 1
                                • 2
                                • 2 / 2
                                • First post
                                  Last post