<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LAPS &#8211; RAGASYS SISTEMAS</title>
	<atom:link href="https://blog.ragasys.es/category/laps/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.ragasys.es</link>
	<description>Soporte técnico para las TIC</description>
	<lastBuildDate>Mon, 26 Aug 2024 06:53:48 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/05/logoRGS_18_05_2020.png?fit=32%2C32&#038;ssl=1</url>
	<title>LAPS &#8211; RAGASYS SISTEMAS</title>
	<link>https://blog.ragasys.es</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">111701399</site>	<item>
		<title>Migrar Microsoft LAPS a Windows LAPS</title>
		<link>https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps</link>
					<comments>https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 26 Aug 2024 06:44:28 +0000</pubDate>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[LAPS]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[TIC]]></category>
		<category><![CDATA[Windows LAPS]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=18187</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo migrar del antiguo Microsoft LAPS al nuevo Windows LAPS, en nuestra infraestructura, tenemos dos controladores de dominio con Windows Server 2019 y el antiguo sistema Microsoft LAPS implantado, en este&#8230; <a href="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo migrar del antiguo Microsoft LAPS al nuevo Windows LAPS, en nuestra infraestructura, tenemos dos controladores de dominio con Windows Server 2019 y el antiguo sistema Microsoft LAPS implantado, <a href="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution" target="_blank" rel="noopener">en este link podemos ver como lo implantamos</a>.</p>
<ul>
<li>Antes de empezar, si tenemos configurado el <a href="https://blog.ragasys.es/configurar-gpo-central-store" target="_blank" rel="noopener">almacén central</a> para nuestras GPO, tendremos que copiar la carpeta <strong>PolicyDefinitions</strong> ubicada en <strong>C:\Windows</strong>, a la carpeta de <strong>SYSVOL</strong> dónde residen las políticas de grupo del dominio Active Directory, <strong>C:\Windows\SYSVOL\sysvol\dominioAD\Policies</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?ssl=1" data-lbwps-width="1030" data-lbwps-height="731" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18188" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?fit=1030%2C731&amp;ssl=1" data-orig-size="1030,731" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?fit=640%2C454&amp;ssl=1" class="aligncenter size-full wp-image-18188" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?resize=640%2C454&#038;ssl=1" alt="" width="640" height="454" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?w=1030&amp;ssl=1 1030w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?resize=595%2C422&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?resize=960%2C681&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_1.png?resize=768%2C545&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?ssl=1" data-lbwps-width="1028" data-lbwps-height="613" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18189" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?fit=1028%2C613&amp;ssl=1" data-orig-size="1028,613" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?fit=640%2C381&amp;ssl=1" class="aligncenter size-full wp-image-18189" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?resize=640%2C382&#038;ssl=1" alt="" width="640" height="382" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?w=1028&amp;ssl=1 1028w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?resize=595%2C355&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?resize=960%2C572&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_2.png?resize=768%2C458&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a migrar de Microsoft LAPS a Windows LAPS, para ello, seguimos <a href="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022" target="_blank" rel="noopener">este post que realizamos anteriormente</a>, para implantar Windows LAPS, pero las dos nuevas GPOs que nos hemos creado (LAPS_Equipos y LAPS_Servidores) no las vamos a vincular de momento a ninguna Unidad Organizativa (OU), esto lo haremos en un paso posterior, aquí vemos las dos GPOs que nos hemos creado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?ssl=1" data-lbwps-width="1652" data-lbwps-height="903" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3-1536x840.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18190" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?fit=1652%2C903&amp;ssl=1" data-orig-size="1652,903" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?fit=640%2C350&amp;ssl=1" class="aligncenter size-full wp-image-18190" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?resize=640%2C350&#038;ssl=1" alt="" width="640" height="350" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?w=1652&amp;ssl=1 1652w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?resize=595%2C325&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?resize=960%2C525&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?resize=768%2C420&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?resize=1536%2C840&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?ssl=1" data-lbwps-width="1657" data-lbwps-height="904" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4-1536x838.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18191" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?fit=1657%2C904&amp;ssl=1" data-orig-size="1657,904" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?fit=640%2C349&amp;ssl=1" class="aligncenter size-full wp-image-18191" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?resize=640%2C349&#038;ssl=1" alt="" width="640" height="349" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?w=1657&amp;ssl=1 1657w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?resize=595%2C325&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?resize=960%2C524&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?resize=768%2C419&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?resize=1536%2C838&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_4.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>El siguiente paso para seguir con la migración, es desvincular la GPO de LAPS antigua o heredada de las Unidades Organizativas donde esté:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?ssl=1" data-lbwps-width="1053" data-lbwps-height="719" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18192" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?fit=1053%2C719&amp;ssl=1" data-orig-size="1053,719" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?fit=640%2C437&amp;ssl=1" class="aligncenter size-full wp-image-18192" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?resize=640%2C437&#038;ssl=1" alt="" width="640" height="437" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?w=1053&amp;ssl=1 1053w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?resize=595%2C406&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?resize=960%2C655&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_5.png?resize=768%2C524&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?ssl=1" data-lbwps-width="963" data-lbwps-height="837" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18193" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?fit=963%2C837&amp;ssl=1" data-orig-size="963,837" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?fit=640%2C556&amp;ssl=1" class="aligncenter size-full wp-image-18193" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?resize=640%2C556&#038;ssl=1" alt="" width="640" height="556" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?w=963&amp;ssl=1 963w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?resize=595%2C517&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?resize=960%2C834&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_6.png?resize=768%2C668&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a vincular las dos nuevas GPOs creadas, <strong>LAPS_Equipos y LAPS_Servidores</strong>, sobre las unidades organizativas que nos interese:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?ssl=1" data-lbwps-width="1083" data-lbwps-height="688" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18194" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?fit=1083%2C688&amp;ssl=1" data-orig-size="1083,688" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?fit=640%2C407&amp;ssl=1" class="aligncenter size-full wp-image-18194" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?resize=640%2C407&#038;ssl=1" alt="" width="640" height="407" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?w=1083&amp;ssl=1 1083w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?resize=595%2C378&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?resize=960%2C610&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_7.png?resize=768%2C488&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Verificamos en cualquier equipo de nuestra infraestructura que todo lo configurado se está aplicando, empezamos ejecutando los comandos <strong>gpupdate /force</strong> y <strong>gpresult /r:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?ssl=1" data-lbwps-width="990" data-lbwps-height="849" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18195" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?fit=990%2C849&amp;ssl=1" data-orig-size="990,849" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?fit=640%2C549&amp;ssl=1" class="aligncenter size-full wp-image-18195" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?resize=640%2C549&#038;ssl=1" alt="" width="640" height="549" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?w=990&amp;ssl=1 990w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?resize=595%2C510&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?resize=960%2C823&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_8.png?resize=768%2C659&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora para ver la password del administrador local de los equipos, accedemos a cualquiera de nuestros controladores de dominio, accedemos a la consola de Usuarios y equipos de Active Directory, y abrimos las propiedades de cualquier equipo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?ssl=1" data-lbwps-width="1659" data-lbwps-height="926" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9-1536x857.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18196" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?fit=1659%2C926&amp;ssl=1" data-orig-size="1659,926" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?fit=640%2C357&amp;ssl=1" class="aligncenter size-full wp-image-18196" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?resize=640%2C357&#038;ssl=1" alt="" width="640" height="357" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?w=1659&amp;ssl=1 1659w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?resize=595%2C332&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?resize=960%2C536&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?resize=768%2C429&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?resize=1536%2C857&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos a la pestaña <strong>LAPS</strong>, y desde aquí podemos ver el <strong>Nombre de la cuenta de administrador local de LAPS</strong>, la <strong>Contraseña de la cuenta de administrador local de LAPS (Copiar y Mostrar)</strong>, podemos ver la <strong>Expiración actual de contraseña de LAPS</strong>, y <strong>Establecer nueva expiración de contraseña de LAPS</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?ssl=1" data-lbwps-width="1160" data-lbwps-height="736" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18197" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?fit=1160%2C736&amp;ssl=1" data-orig-size="1160,736" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?fit=640%2C406&amp;ssl=1" class="aligncenter size-full wp-image-18197" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?resize=640%2C406&#038;ssl=1" alt="" width="640" height="406" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?w=1160&amp;ssl=1 1160w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?resize=595%2C378&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?resize=960%2C609&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_10.png?resize=768%2C487&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si nos abrimos un PowerShell en cualquiera de nuestros controladores de dominio, y ejecutamos primero el comando <strong>Get-Command -Module LAPS</strong>, para ver los comandos disponibles en el módulo de LAPS:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?ssl=1" data-lbwps-width="1103" data-lbwps-height="436" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18198" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?fit=1103%2C436&amp;ssl=1" data-orig-size="1103,436" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?fit=640%2C253&amp;ssl=1" class="aligncenter size-full wp-image-18198" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?resize=640%2C253&#038;ssl=1" alt="" width="640" height="253" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?w=1103&amp;ssl=1 1103w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?resize=595%2C235&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?resize=960%2C379&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_11.png?resize=768%2C304&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ejecutando el comando <strong>Get-LapsADPassword “nombreequipo” -AsPlainText</strong>, podemos ver, la cuenta del administrador local del equipo con su contraseña:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?ssl=1" data-lbwps-width="1033" data-lbwps-height="624" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18199" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?fit=1033%2C624&amp;ssl=1" data-orig-size="1033,624" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?fit=640%2C387&amp;ssl=1" class="aligncenter size-full wp-image-18199" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?resize=640%2C387&#038;ssl=1" alt="" width="640" height="387" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?w=1033&amp;ssl=1 1033w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?resize=595%2C359&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?resize=960%2C580&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_12.png?resize=768%2C464&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para terminar, eliminamos el software de LAPS heredada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?ssl=1" data-lbwps-width="1037" data-lbwps-height="479" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18200" data-permalink="https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/mmslapsawinlaps_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?fit=1037%2C479&amp;ssl=1" data-orig-size="1037,479" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="mmslapsawinlaps_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-18200" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?resize=640%2C296&#038;ssl=1" alt="" width="640" height="296" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?w=1037&amp;ssl=1 1037w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?resize=595%2C275&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?resize=960%2C443&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/mmslapsawinlaps_13.png?resize=768%2C355&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/migrar-microsoft-laps-a-windows-laps/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18187</post-id>	</item>
		<item>
		<title>Configurar Windows LAPS para contraseña DSRM de Active Directory</title>
		<link>https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory</link>
					<comments>https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 05 Aug 2024 07:13:50 +0000</pubDate>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Controladores de dominio]]></category>
		<category><![CDATA[Domain Controllers]]></category>
		<category><![CDATA[LAPS]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[TIC]]></category>
		<category><![CDATA[Windows LAPS]]></category>
		<category><![CDATA[Windows Server 2019]]></category>
		<category><![CDATA[Windows Server 2022]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=18173</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo configurar Windows LAPS para la contraseña DSRM (restauración de servicios de directorio) de Active Directory, esta contraseña la asignamos cuando desplegamos el rol de Servicios de dominio de Active Directory,&#8230; <a href="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo configurar Windows LAPS para la contraseña DSRM (restauración de servicios de directorio) de Active Directory, esta contraseña la asignamos cuando desplegamos el rol de Servicios de dominio de Active Directory, esta es una nueva característica del nuevo Windows LAPS.</p>
<ul>
<li>Lo primero que vamos a realizar es acceder a uno de nuestros controladores de dominio y nos abrimos la consola de <strong>Usuarios y equipos de Active Directory</strong>, nos vamos a la Unidad Organizativa (OU) <strong>Domain Controllers</strong>, damos <strong>Propiedades</strong> sobre uno de ellos, y sobre la pestaña <strong>LAPS</strong> podemos ver, que es aquí dónde nos va a mostrar la contraseña de DSRM, una vez que tengamos la GPO configurada y vinculada sobre la OU Domain Controllers:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?ssl=1" data-lbwps-width="994" data-lbwps-height="494" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18174" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?fit=994%2C494&amp;ssl=1" data-orig-size="994,494" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?fit=640%2C318&amp;ssl=1" class="aligncenter size-full wp-image-18174" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?resize=640%2C318&#038;ssl=1" alt="" width="640" height="318" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?w=994&amp;ssl=1 994w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?resize=595%2C296&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?resize=960%2C477&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_1.png?resize=768%2C382&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?ssl=1" data-lbwps-width="986" data-lbwps-height="731" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18175" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?fit=986%2C731&amp;ssl=1" data-orig-size="986,731" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?fit=640%2C475&amp;ssl=1" class="aligncenter size-full wp-image-18175" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?resize=640%2C474&#038;ssl=1" alt="" width="640" height="474" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?w=986&amp;ssl=1 986w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?resize=595%2C441&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?resize=960%2C712&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_2.png?resize=768%2C569&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos abrimos la consola <strong>Administración de directivas de grupo</strong> y nos vamos a crear una nueva <strong>GPO</strong> llamada <strong>LAPS_DSRM </strong>con la siguiente configuración:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?ssl=1" data-lbwps-width="1651" data-lbwps-height="905" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3-1536x842.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18176" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?fit=1651%2C905&amp;ssl=1" data-orig-size="1651,905" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?fit=640%2C351&amp;ssl=1" class="aligncenter size-full wp-image-18176" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?resize=640%2C351&#038;ssl=1" alt="" width="640" height="351" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?w=1651&amp;ssl=1 1651w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?resize=595%2C326&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?resize=960%2C526&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?resize=768%2C421&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?resize=1536%2C842&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Luego vinculamos esta GPO sobre la OU Domain Controllers:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?ssl=1" data-lbwps-width="1651" data-lbwps-height="496" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4-1536x461.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18177" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?fit=1651%2C496&amp;ssl=1" data-orig-size="1651,496" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?fit=640%2C192&amp;ssl=1" class="aligncenter size-full wp-image-18177" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?resize=640%2C192&#038;ssl=1" alt="" width="640" height="192" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?w=1651&amp;ssl=1 1651w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?resize=595%2C179&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?resize=960%2C288&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?resize=768%2C231&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?resize=1536%2C461&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_4.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si nos abrimos un PowerShell sobre el controlador de dominio DCRGS01 y ejecutamos un <strong>gpupdate /force</strong>, vamos a forzar a que se activen estas nuevas configuraciones de directivas que hemos creado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?ssl=1" data-lbwps-width="995" data-lbwps-height="344" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18178" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?fit=995%2C344&amp;ssl=1" data-orig-size="995,344" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?fit=640%2C221&amp;ssl=1" class="aligncenter size-full wp-image-18178" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?resize=640%2C221&#038;ssl=1" alt="" width="640" height="221" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?w=995&amp;ssl=1 995w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?resize=595%2C206&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?resize=960%2C332&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_5.png?resize=768%2C266&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos de nuevo a la consola de <strong>Usuarios y equipos de Active Directory</strong>, nos vamos a la Unidad Organizativa (OU) <strong>Domain Controllers</strong>, damos <strong>Propiedades</strong> sobre DCRGS01, y sobre la pestaña <strong>LAPS</strong> podemos ver, que ya se ha aplicado esta nueva GPO para controlar las contraseñas de DSRM de los controladores de dominio de nuestra infraestructura:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?ssl=1" data-lbwps-width="994" data-lbwps-height="494" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18179" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?fit=994%2C494&amp;ssl=1" data-orig-size="994,494" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?fit=640%2C318&amp;ssl=1" class="aligncenter size-full wp-image-18179" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?resize=640%2C318&#038;ssl=1" alt="" width="640" height="318" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?w=994&amp;ssl=1 994w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?resize=595%2C296&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?resize=960%2C477&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_6.png?resize=768%2C382&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?ssl=1" data-lbwps-width="983" data-lbwps-height="726" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18180" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?fit=983%2C726&amp;ssl=1" data-orig-size="983,726" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?fit=640%2C473&amp;ssl=1" class="aligncenter size-full wp-image-18180" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?resize=640%2C473&#038;ssl=1" alt="" width="640" height="473" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?w=983&amp;ssl=1 983w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?resize=595%2C439&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?resize=960%2C709&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_7.png?resize=768%2C567&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si nos abrimos un PowerShell sobre el controlador de dominio DCRGS02 y ejecutamos un <strong>gpupdate /force</strong>, vamos a forzar a que se activen estas nuevas configuraciones de directivas que hemos creado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?ssl=1" data-lbwps-width="998" data-lbwps-height="339" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18181" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?fit=998%2C339&amp;ssl=1" data-orig-size="998,339" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?fit=640%2C217&amp;ssl=1" class="aligncenter size-full wp-image-18181" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?resize=640%2C217&#038;ssl=1" alt="" width="640" height="217" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?w=998&amp;ssl=1 998w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?resize=595%2C202&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?resize=960%2C326&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_8.png?resize=768%2C261&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos de nuevo a la consola de <strong>Usuarios y equipos de Active Directory</strong>, nos vamos a la Unidad Organizativa (OU) <strong>Domain Controllers</strong>, damos <strong>Propiedades</strong> sobre DCRGS02, y sobre la pestaña <strong>LAPS</strong> podemos ver, que ya se ha aplicado esta nueva GPO para controlar las contraseñas de DSRM de los controladores de dominio de nuestra infraestructura:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?ssl=1" data-lbwps-width="935" data-lbwps-height="450" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18182" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?fit=935%2C450&amp;ssl=1" data-orig-size="935,450" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?fit=640%2C308&amp;ssl=1" class="aligncenter size-full wp-image-18182" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?resize=640%2C308&#038;ssl=1" alt="" width="640" height="308" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?w=935&amp;ssl=1 935w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?resize=595%2C286&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_9.png?resize=768%2C370&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?ssl=1" data-lbwps-width="925" data-lbwps-height="728" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18183" data-permalink="https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/cwlapspcdsrmdad_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?fit=925%2C728&amp;ssl=1" data-orig-size="925,728" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwlapspcdsrmdad_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?fit=640%2C504&amp;ssl=1" class="aligncenter size-full wp-image-18183" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?resize=640%2C504&#038;ssl=1" alt="" width="640" height="504" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?w=925&amp;ssl=1 925w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?resize=595%2C468&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/cwlapspcdsrmdad_10.png?resize=768%2C604&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configurar-windows-laps-para-contrasena-dsrm-de-active-directory/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18173</post-id>	</item>
		<item>
		<title>Instalar y configurar Windows LAPS (Local Administrator Password Solution) en Windows Server 2022</title>
		<link>https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022</link>
					<comments>https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 29 Jul 2024 07:39:56 +0000</pubDate>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[LAPS]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[TIC]]></category>
		<category><![CDATA[Windows 10]]></category>
		<category><![CDATA[Windows 11]]></category>
		<category><![CDATA[Windows LAPS]]></category>
		<category><![CDATA[Windows Server 2019]]></category>
		<category><![CDATA[Windows Server 2022]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=18142</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo instalar y configurar Windows LAPS (Local Administrator Password Solution) en Windows Server 2022, LAPS determina si la contraseña de la cuenta del administrador local ha caducado, si la contraseña ha&#8230; <a href="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo instalar y configurar Windows LAPS (Local Administrator Password Solution) en Windows Server 2022, LAPS determina si la contraseña de la cuenta del administrador local ha caducado, si la contraseña ha caducado, cambia la contraseña del administrador local a un nuevo valor aleatorio y transmite la nueva contraseña y la fecha de caducidad a Active Directory dónde se almacena en unos atributos especiales asociados con el objeto de equipo de AD. Las contraseñas se almacenan en Active Directory y están protegidas por listas de control de acceso (ACLs) por lo que solo los usuarios elegibles pueden leerlas o solicitar su restablecimiento.</p>
<ul>
<li>Los requisitos para configurar esta nueva implementación de LAPS, son los siguientes, ya que anteriormente a estas nuevas actualizaciones, LAPS había que implementarlo de forma manual, <a href="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution" target="_blank" rel="noopener">en este link os dejo como se hacía anterior a estas actualizaciones</a>, con estas nuevas actualizaciones LAPS se implementa de forma nativa en estos sistemas:</li>
<li>Windows 11 22H2 – Actualización 11 abril 2023</li>
<li>Windows 11 21H2 – Actualización 11 abril 2023</li>
<li>Windows 10 – Actualización 11 abril 2023</li>
<li>Windows Server 2019 – Actualización 11 abril 2023</li>
<li>Windows Server 2022 – Actualización 11 abril 2023</li>
<li>Para implementar y configurar este laboratorio, he utilizado dos máquinas Windows Server 2022 Standard como Controladores de dominio, uno principal y otro adicional, una máquina Windows Server 2022 Standard y otra con Windows 11 Pro, que serán miembros del dominio ragasys.local implementado en los dos controladores de dominio:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png?ssl=1" data-lbwps-width="557" data-lbwps-height="561" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18143" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png?fit=557%2C561&amp;ssl=1" data-orig-size="557,561" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png?fit=557%2C561&amp;ssl=1" class="aligncenter size-full wp-image-18143" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png?resize=557%2C561&#038;ssl=1" alt="" width="557" height="561" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png?w=557&amp;ssl=1 557w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_1.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 557px) 100vw, 557px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png?ssl=1" data-lbwps-width="561" data-lbwps-height="556" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18144" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png?fit=561%2C556&amp;ssl=1" data-orig-size="561,556" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png?fit=561%2C556&amp;ssl=1" class="aligncenter size-full wp-image-18144" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png?resize=561%2C556&#038;ssl=1" alt="" width="561" height="556" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png?w=561&amp;ssl=1 561w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_2.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 561px) 100vw, 561px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_3.png?ssl=1" data-lbwps-width="562" data-lbwps-height="591" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18145" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_3.png?fit=562%2C591&amp;ssl=1" data-orig-size="562,591" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_3.png?fit=562%2C591&amp;ssl=1" class="aligncenter size-full wp-image-18145" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_3.png?resize=562%2C591&#038;ssl=1" alt="" width="562" height="591" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_4.png?ssl=1" data-lbwps-width="537" data-lbwps-height="593" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18146" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_4.png?fit=537%2C593&amp;ssl=1" data-orig-size="537,593" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_4.png?fit=537%2C593&amp;ssl=1" class="aligncenter size-full wp-image-18146" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_4.png?resize=537%2C593&#038;ssl=1" alt="" width="537" height="593" /></a></p>
<ul>
<li>Para empezar, vamos a extender el schema de Active Directory, para que se añadan los atributos nuevos a las propiedades de los equipos de nuestra infraestructura, para ello, accedemos a nuestro controlador de dominio principal, dcrgs01, nos abrimos un PowerShell y nos importamos los módulos de LAPS con el comando <strong>Import-Module LAPS</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?ssl=1" data-lbwps-width="1114" data-lbwps-height="349" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18147" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?fit=1114%2C349&amp;ssl=1" data-orig-size="1114,349" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?fit=640%2C201&amp;ssl=1" class="aligncenter size-full wp-image-18147" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?resize=640%2C201&#038;ssl=1" alt="" width="640" height="201" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?w=1114&amp;ssl=1 1114w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?resize=595%2C186&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?resize=960%2C301&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_5.png?resize=768%2C241&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para ver los comandos disponibles en este módulo ejecutamos <strong>Get-Command -Module LAPS</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?ssl=1" data-lbwps-width="1109" data-lbwps-height="633" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18148" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?fit=1109%2C633&amp;ssl=1" data-orig-size="1109,633" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?fit=640%2C365&amp;ssl=1" class="aligncenter size-full wp-image-18148" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?resize=640%2C365&#038;ssl=1" alt="" width="640" height="365" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?w=1109&amp;ssl=1 1109w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?resize=595%2C340&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?resize=960%2C548&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_6.png?resize=768%2C438&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para extender el schema de nuestro Active Directory y soportar toda la configuración de LAPS, vamos a utilizar el comando <strong>Update-LapsADSchema</strong>, le indicamos que Si (S) uno a uno o podemos indicarle que Sí a todo (O), aquí he elegido la primera opción, para mostrar todos los atributos que se van a añadir en las propiedades de los equipos de nuestra infraestructura de dominio:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?ssl=1" data-lbwps-width="1112" data-lbwps-height="866" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18149" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?fit=1112%2C866&amp;ssl=1" data-orig-size="1112,866" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?fit=640%2C499&amp;ssl=1" class="aligncenter size-full wp-image-18149" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?resize=640%2C498&#038;ssl=1" alt="" width="640" height="498" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?w=1112&amp;ssl=1 1112w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?resize=595%2C463&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?resize=960%2C748&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_7.png?resize=768%2C598&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para verificar que los atributos se han añadido correctamente a nuestros equipos, sobre nuestro controlador de dominio principal, accedemos a Usuarios y equipos de Active Directory y abrimos las propiedades de cualquier equipo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?ssl=1" data-lbwps-width="926" data-lbwps-height="507" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18150" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?fit=926%2C507&amp;ssl=1" data-orig-size="926,507" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?fit=640%2C350&amp;ssl=1" class="aligncenter size-full wp-image-18150" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?resize=640%2C350&#038;ssl=1" alt="" width="640" height="350" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?w=926&amp;ssl=1 926w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?resize=595%2C326&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_8.png?resize=768%2C420&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos a la pestaña <strong>Editor de atributos</strong>, y como podemos ver, ya se han añadido los atributos de LAPS a los equipos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?ssl=1" data-lbwps-width="1120" data-lbwps-height="778" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18151" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?fit=1120%2C778&amp;ssl=1" data-orig-size="1120,778" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?fit=640%2C445&amp;ssl=1" class="aligncenter size-full wp-image-18151" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?resize=640%2C445&#038;ssl=1" alt="" width="640" height="445" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?w=1120&amp;ssl=1 1120w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?resize=595%2C413&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?resize=960%2C667&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?resize=768%2C533&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_9.png?resize=250%2C175&amp;ssl=1 250w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a establecer los permisos para LAPS en las Unidades Organizativas (OU) que nos interesen, en este caso, las OUs que vamos a utilizar serán las de <strong>Equipos</strong> para las máquinas clientes y la de <strong>Servidores</strong> para las máquinas con el rol de servidor, estos permisos va a permitir a LAPS modificar los atributos de las cuentas de equipos que se encuentran en estas OUs, permitiendo así crear y modificar las contraseñas, para ello ejecutamos el comando, <strong>Set-LapsADComputerSelfPermission -Identity “DistinguisedName OU”</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?ssl=1" data-lbwps-width="1112" data-lbwps-height="441" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18152" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?fit=1112%2C441&amp;ssl=1" data-orig-size="1112,441" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?fit=640%2C254&amp;ssl=1" class="aligncenter size-full wp-image-18152" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?resize=640%2C254&#038;ssl=1" alt="" width="640" height="254" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?w=1112&amp;ssl=1 1112w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?resize=595%2C236&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?resize=960%2C381&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_10.png?resize=768%2C305&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar las GPOs para LAPS en Active Directory, en nuestro caso, vamos a configurar dos GPOs, una para los equipos clientes llamada <strong>LAPS_Equipos</strong> y otra para los servidores llamada <strong>LAPS_Servidores</strong>, habilitamos la política y en el caso de que el administrador local no sea el nombre por defecto (Administrator o Administrador) indicamos el nombre de la cuenta local tipo administrador que esté configurada en los equipos del dominio y los parámetros de las passwords como la complejidad, longitud y expiración, estas serían las dos GPOs configuradas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?ssl=1" data-lbwps-width="1654" data-lbwps-height="902" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11-1536x838.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18153" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?fit=1654%2C902&amp;ssl=1" data-orig-size="1654,902" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?fit=640%2C349&amp;ssl=1" class="aligncenter size-full wp-image-18153" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?resize=640%2C349&#038;ssl=1" alt="" width="640" height="349" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?w=1654&amp;ssl=1 1654w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?resize=595%2C324&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?resize=960%2C524&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?resize=768%2C419&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?resize=1536%2C838&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?ssl=1" data-lbwps-width="1661" data-lbwps-height="847" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12-1536x783.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18154" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?fit=1661%2C847&amp;ssl=1" data-orig-size="1661,847" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?fit=640%2C327&amp;ssl=1" class="aligncenter size-full wp-image-18154" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?resize=640%2C326&#038;ssl=1" alt="" width="640" height="326" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?w=1661&amp;ssl=1 1661w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?resize=595%2C303&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?resize=960%2C490&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?resize=768%2C392&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?resize=1536%2C783&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez que tenemos creadas las GPOs las vamos a vincular sobre las unidades organizativas que indicamos anteriormente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?ssl=1" data-lbwps-width="1649" data-lbwps-height="538" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13-1536x501.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18155" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?fit=1649%2C538&amp;ssl=1" data-orig-size="1649,538" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?fit=640%2C209&amp;ssl=1" class="aligncenter size-full wp-image-18155" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?resize=640%2C209&#038;ssl=1" alt="" width="640" height="209" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?w=1649&amp;ssl=1 1649w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?resize=595%2C194&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?resize=960%2C313&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?resize=768%2C251&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?resize=1536%2C501&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?ssl=1" data-lbwps-width="1652" data-lbwps-height="551" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14-1536x512.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18156" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?fit=1652%2C551&amp;ssl=1" data-orig-size="1652,551" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?fit=640%2C213&amp;ssl=1" class="aligncenter size-full wp-image-18156" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?resize=640%2C213&#038;ssl=1" alt="" width="640" height="213" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?w=1652&amp;ssl=1 1652w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?resize=595%2C198&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?resize=960%2C320&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?resize=768%2C256&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?resize=1536%2C512&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con esto ya tendríamos implementado y configurado LAPS en nuestra infraestructura, lo primero que vamos a verificar es que la GPO se está aplicando en los equipos de cada unidad organizativa, para ello, en cualquiera de los equipos de ambas unidades organizativas ejecutamos el comando <strong>gpresult /r</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?ssl=1" data-lbwps-width="1196" data-lbwps-height="920" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18157" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?fit=1196%2C920&amp;ssl=1" data-orig-size="1196,920" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?fit=640%2C492&amp;ssl=1" class="aligncenter size-full wp-image-18157" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?resize=640%2C492&#038;ssl=1" alt="" width="640" height="492" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?w=1196&amp;ssl=1 1196w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?resize=595%2C458&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?resize=960%2C738&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_15.png?resize=768%2C591&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?ssl=1" data-lbwps-width="1075" data-lbwps-height="827" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18158" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?fit=1075%2C827&amp;ssl=1" data-orig-size="1075,827" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?fit=640%2C493&amp;ssl=1" class="aligncenter size-full wp-image-18158" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?resize=640%2C492&#038;ssl=1" alt="" width="640" height="492" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?w=1075&amp;ssl=1 1075w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?resize=595%2C458&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?resize=960%2C739&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_16.png?resize=768%2C591&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora para ver la password del administrador local de los equipos, accedemos a cualquiera de nuestros controladores de dominio, accedemos a la consola de Usuarios y equipos de Active Directory, y abrimos las propiedades de cualquier equipo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?ssl=1" data-lbwps-width="926" data-lbwps-height="507" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18159" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?fit=926%2C507&amp;ssl=1" data-orig-size="926,507" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?fit=640%2C350&amp;ssl=1" class="aligncenter size-full wp-image-18159" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?resize=640%2C350&#038;ssl=1" alt="" width="640" height="350" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?w=926&amp;ssl=1 926w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?resize=595%2C326&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_17.png?resize=768%2C420&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos a la pestaña <strong>LAPS</strong>, y desde aquí podemos ver el <strong>Nombre de la cuenta de administrador local de LAPS</strong>, la <strong>Contraseña de la cuenta de administrador local de LAPS (Copiar y Mostrar)</strong>, podemos ver la <strong>Expiración actual de contraseña de LAPS</strong>, y <strong>Establecer nueva expiración de contraseña de LAPS</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?ssl=1" data-lbwps-width="926" data-lbwps-height="724" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18160" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?fit=926%2C724&amp;ssl=1" data-orig-size="926,724" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?fit=640%2C500&amp;ssl=1" class="aligncenter size-full wp-image-18160" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?resize=640%2C500&#038;ssl=1" alt="" width="640" height="500" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?w=926&amp;ssl=1 926w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?resize=595%2C465&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_18.png?resize=768%2C600&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?ssl=1" data-lbwps-width="916" data-lbwps-height="715" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18161" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?fit=916%2C715&amp;ssl=1" data-orig-size="916,715" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?fit=640%2C500&amp;ssl=1" class="aligncenter size-full wp-image-18161" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?resize=640%2C500&#038;ssl=1" alt="" width="640" height="500" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?w=916&amp;ssl=1 916w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?resize=595%2C464&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_19.png?resize=768%2C599&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si nos abrimos un PowerShell en cualquiera de nuestros controladores de dominio, y ejecutamos primero el comando <strong>Get-Command -Module LAPS</strong>, para ver los comandos disponibles en el módulo de LAPS:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?ssl=1" data-lbwps-width="1103" data-lbwps-height="472" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18162" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?fit=1103%2C472&amp;ssl=1" data-orig-size="1103,472" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?fit=640%2C274&amp;ssl=1" class="aligncenter size-full wp-image-18162" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?resize=640%2C274&#038;ssl=1" alt="" width="640" height="274" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?w=1103&amp;ssl=1 1103w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?resize=595%2C255&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?resize=960%2C411&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_20.png?resize=768%2C329&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ejecutando el comando <strong>Get-LapsADPassword “nombreequipo” -AsPlainText</strong>, podemos ver, la cuenta del administrador local del equipo con su contraseña:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?ssl=1" data-lbwps-width="1106" data-lbwps-height="930" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18163" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?fit=1106%2C930&amp;ssl=1" data-orig-size="1106,930" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?fit=640%2C538&amp;ssl=1" class="aligncenter size-full wp-image-18163" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?resize=640%2C538&#038;ssl=1" alt="" width="640" height="538" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?w=1106&amp;ssl=1 1106w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?resize=595%2C500&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?resize=960%2C807&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_21.png?resize=768%2C646&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sólo los usuarios Administradores del dominio tienen permisos de lectura y escritura sobre los valores de los atributos donde se almacena la password y la fecha de expiración, en muchas ocasiones, necesitamos dar permisos a otros usuarios, por lo que vamos a crear este grupo, LAPS_HelpDesk, y dentro de este grupo añadiremos a los usuarios o grupos que nos interesen, si hacemos esto, el grupo Administradores del dominio también lo tenemos que añadir al grupo, ya que si no, no podremos visualizar las contraseñas con las cuentas de administrador:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?ssl=1" data-lbwps-width="1042" data-lbwps-height="665" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18164" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?fit=1042%2C665&amp;ssl=1" data-orig-size="1042,665" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?fit=640%2C409&amp;ssl=1" class="aligncenter size-full wp-image-18164" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?resize=640%2C408&#038;ssl=1" alt="" width="640" height="408" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?w=1042&amp;ssl=1 1042w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?resize=595%2C380&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?resize=960%2C613&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_22.png?resize=768%2C490&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora tenemos que volver a configurar las dos GPOs que creamos anteriormente y habilitar estas dos opciones, <strong>Habilitar cifrado de contraseña y Configurar descifradores de contraseñas autorizados</strong> que incluiremos al grupo que hemos creado anteriormente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?ssl=1" data-lbwps-width="1659" data-lbwps-height="919" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23-1536x851.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18165" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?fit=1659%2C919&amp;ssl=1" data-orig-size="1659,919" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?fit=640%2C355&amp;ssl=1" class="aligncenter size-full wp-image-18165" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?resize=640%2C355&#038;ssl=1" alt="" width="640" height="355" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?w=1659&amp;ssl=1 1659w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?resize=595%2C330&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?resize=960%2C532&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?resize=768%2C425&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?resize=1536%2C851&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_23.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?ssl=1" data-lbwps-width="1653" data-lbwps-height="915" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24-1536x850.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18166" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?fit=1653%2C915&amp;ssl=1" data-orig-size="1653,915" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?fit=640%2C354&amp;ssl=1" class="aligncenter size-full wp-image-18166" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?resize=640%2C354&#038;ssl=1" alt="" width="640" height="354" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?w=1653&amp;ssl=1 1653w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?resize=595%2C329&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?resize=960%2C531&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?resize=768%2C425&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?resize=1536%2C850&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_24.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora asignamos los permisos para el grupo LAPS_HelpDesk.</li>
<li>Con este comando asignamos los permisos de lectura sobre la OU especificada:</li>
<li><strong>Set-LapsADReadPasswordPermission -Identity “distinguisedname OU” -AllowedPrincipals “DOMINIO\GRUPO”</strong></li>
<li>Con este comando asignamos los permisos de lectura-escritura sobre la OU especificada:</li>
<li><strong>Set-LapsADResetPasswordPermission -Identity</strong> <strong>“distinguisedname OU” -AllowedPrincipals “DOMINIO\GRUPO”</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?ssl=1" data-lbwps-width="1552" data-lbwps-height="634" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25-1536x627.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18167" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?fit=1552%2C634&amp;ssl=1" data-orig-size="1552,634" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?fit=640%2C261&amp;ssl=1" class="aligncenter size-full wp-image-18167" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?resize=640%2C261&#038;ssl=1" alt="" width="640" height="261" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?w=1552&amp;ssl=1 1552w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?resize=595%2C243&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?resize=960%2C392&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?resize=768%2C314&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?resize=1536%2C627&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_25.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con el siguiente cmdlet verificamos la asignación de permisos asignados a las Unidades Organizativas, <strong>Find-LapsADExtendedRights -Identity “distinguisedname OU”</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?ssl=1" data-lbwps-width="1148" data-lbwps-height="694" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18168" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?fit=1148%2C694&amp;ssl=1" data-orig-size="1148,694" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?fit=640%2C387&amp;ssl=1" class="aligncenter size-full wp-image-18168" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?resize=640%2C387&#038;ssl=1" alt="" width="640" height="387" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?w=1148&amp;ssl=1 1148w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?resize=595%2C360&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?resize=960%2C580&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_26.png?resize=768%2C464&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si accedemos a cualquier equipo de nuestra infraestructura, con el usuario ubicado en el grupo LAPS_HelpDesk, podemos ver las credenciales del usuario local administrador y resetear las contraseñas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?ssl=1" data-lbwps-width="1164" data-lbwps-height="923" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18169" data-permalink="https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/iycwlapsews2022_27#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?fit=1164%2C923&amp;ssl=1" data-orig-size="1164,923" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iycwlapsews2022_27" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?fit=640%2C507&amp;ssl=1" class="aligncenter size-full wp-image-18169" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?resize=640%2C507&#038;ssl=1" alt="" width="640" height="507" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?w=1164&amp;ssl=1 1164w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?resize=595%2C472&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?resize=960%2C761&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/07/iycwlapsews2022_27.png?resize=768%2C609&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/instalar-y-configurar-windows-laps-local-administrator-password-solution-en-windows-server-2022/feed</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18142</post-id>	</item>
		<item>
		<title>GPO para LAPS con cuenta nativa administrativa</title>
		<link>https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa</link>
					<comments>https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 25 Sep 2023 07:12:08 +0000</pubDate>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[LAPS]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Seguridad]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16840</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver una configuración de GPO para LAPS alternativa a la que realizamos en el post anterior, ya que en la anterior GPO le indicamos una cuenta de usuario administrador, en esta nueva&#8230; <a href="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver una configuración de GPO para LAPS alternativa a la que realizamos en el post anterior, ya que en la anterior GPO le indicamos una cuenta de usuario administrador, en esta nueva GPO, no utilizaremos ninguna cuenta de administrador, por lo que la password de LAPS se aplicará a la cuenta nativa con permisos de administrador, esta cuenta administrativa se puede llamar administrador, administrator o si la hemos cambiado de nombre tampoco tendríamaos problemas ya que el password se lo aplica por el SID.</p>
<ul>
<li>Como podemos ver, esta es la GPO que utilizamos para el post anterior, dónde en la directiva <strong>Name of administrator account to manage</strong> le indicamos un nombre de cuenta:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?ssl=1" data-lbwps-width="1657" data-lbwps-height="671" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1-1536x622.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16841" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?fit=1657%2C671&amp;ssl=1" data-orig-size="1657,671" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?fit=640%2C259&amp;ssl=1" class="aligncenter size-full wp-image-16841" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?resize=640%2C259&#038;ssl=1" alt="" width="640" height="259" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?w=1657&amp;ssl=1 1657w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?resize=595%2C241&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?resize=960%2C389&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?resize=768%2C311&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?resize=1536%2C622&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_1.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear una nueva directiva dónde <strong>Name of administrator account to manage </strong>la dejaremos en <strong>No configurada</strong>, por lo que, la cuenta nativa de administrador local de nuestros equipos van a utilizar las passwords proporcionadas por LAPS:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?ssl=1" data-lbwps-width="1524" data-lbwps-height="568" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16842" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?fit=1524%2C568&amp;ssl=1" data-orig-size="1524,568" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?fit=640%2C239&amp;ssl=1" class="aligncenter size-full wp-image-16842" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?resize=640%2C239&#038;ssl=1" alt="" width="640" height="239" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?w=1524&amp;ssl=1 1524w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?resize=595%2C222&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?resize=960%2C358&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?resize=768%2C286&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?ssl=1" data-lbwps-width="1629" data-lbwps-height="874" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3-1536x824.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16843" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?fit=1629%2C874&amp;ssl=1" data-orig-size="1629,874" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?fit=640%2C343&amp;ssl=1" class="aligncenter size-full wp-image-16843" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?resize=640%2C343&#038;ssl=1" alt="" width="640" height="343" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?w=1629&amp;ssl=1 1629w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?resize=595%2C319&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?resize=960%2C515&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?resize=768%2C412&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?resize=1536%2C824&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Esta GPO la vamos a vincular sobre una Unidad Organizativa dónde se encuentra uno de nuestros equipos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?ssl=1" data-lbwps-width="1647" data-lbwps-height="514" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4-1536x479.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16844" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?fit=1647%2C514&amp;ssl=1" data-orig-size="1647,514" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?fit=640%2C200&amp;ssl=1" class="aligncenter size-full wp-image-16844" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?resize=640%2C200&#038;ssl=1" alt="" width="640" height="200" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?w=1647&amp;ssl=1 1647w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?resize=595%2C186&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?resize=960%2C300&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?resize=768%2C240&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?resize=1536%2C479&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_4.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?ssl=1" data-lbwps-width="1309" data-lbwps-height="520" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16845" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?fit=1309%2C520&amp;ssl=1" data-orig-size="1309,520" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?fit=640%2C254&amp;ssl=1" class="aligncenter size-full wp-image-16845" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?resize=640%2C254&#038;ssl=1" alt="" width="640" height="254" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?w=1309&amp;ssl=1 1309w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?resize=595%2C236&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?resize=960%2C381&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_5.png?resize=768%2C305&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aplicamos los permisos para la gestión de LAPS en esta Unidad Organizativa, ejecutando el siguiente comando <strong>Set-AdmPwdComputerSelfPermission -OrgUnit &lt;OU&gt;:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?ssl=1" data-lbwps-width="884" data-lbwps-height="245" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16846" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?fit=884%2C245&amp;ssl=1" data-orig-size="884,245" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?fit=640%2C177&amp;ssl=1" class="aligncenter size-full wp-image-16846" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?resize=640%2C177&#038;ssl=1" alt="" width="640" height="177" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?w=884&amp;ssl=1 884w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?resize=595%2C165&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_6.png?resize=768%2C213&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si accedemos a este equipo vemos que tenemos esta cuenta nativa con permisos de administrador, a esta cuenta es a la que se le va aplicar la directiva de LAPS:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?ssl=1" data-lbwps-width="1664" data-lbwps-height="726" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7-1536x670.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16847" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?fit=1664%2C726&amp;ssl=1" data-orig-size="1664,726" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?fit=640%2C279&amp;ssl=1" class="aligncenter size-full wp-image-16847" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?resize=640%2C279&#038;ssl=1" alt="" width="640" height="279" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?w=1664&amp;ssl=1 1664w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?resize=595%2C260&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?resize=960%2C419&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?resize=768%2C335&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?resize=1536%2C670&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Hacemos un <strong>gpupdate /force</strong> para aplicar las políticas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?ssl=1" data-lbwps-width="1364" data-lbwps-height="390" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16848" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?fit=1364%2C390&amp;ssl=1" data-orig-size="1364,390" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?fit=640%2C183&amp;ssl=1" class="aligncenter size-full wp-image-16848" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?resize=640%2C183&#038;ssl=1" alt="" width="640" height="183" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?w=1364&amp;ssl=1 1364w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?resize=595%2C170&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?resize=960%2C274&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?resize=768%2C220&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con <strong>gpresult /r </strong>vemos que esta nueva GPO se está aplicando sobre el equipo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?ssl=1" data-lbwps-width="1349" data-lbwps-height="639" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16849" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?fit=1349%2C639&amp;ssl=1" data-orig-size="1349,639" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?fit=640%2C303&amp;ssl=1" class="aligncenter size-full wp-image-16849" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?resize=640%2C303&#038;ssl=1" alt="" width="640" height="303" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?w=1349&amp;ssl=1 1349w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?resize=595%2C282&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?resize=960%2C455&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?resize=768%2C364&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora para ver la password de los administradores locales de los equipos, accedemos a cualquiera de nuestros controladores de dominio y ejecutamos sobre PowerShell <strong>Get-AdmPwdPassword &lt;HOSTNAME&gt; | fl</strong>, <strong>esta password sería la que debemos de utilizar para la cuenta nativa administrativa que tiene el equipo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?ssl=1" data-lbwps-width="875" data-lbwps-height="303" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16850" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?fit=875%2C303&amp;ssl=1" data-orig-size="875,303" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?fit=640%2C222&amp;ssl=1" class="aligncenter size-full wp-image-16850" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?resize=640%2C222&#038;ssl=1" alt="" width="640" height="222" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?w=875&amp;ssl=1 875w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?resize=595%2C206&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_10.png?resize=768%2C266&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Desde el LAPS UI (ejecutándolo como administrador) del controlador de dominio donde instalamos LAPS también podemos ver el password:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?ssl=1" data-lbwps-width="1297" data-lbwps-height="630" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16851" data-permalink="https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/gpoplapsccna_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?fit=1297%2C630&amp;ssl=1" data-orig-size="1297,630" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpoplapsccna_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?fit=640%2C311&amp;ssl=1" class="aligncenter size-full wp-image-16851" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?resize=640%2C311&#038;ssl=1" alt="" width="640" height="311" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?w=1297&amp;ssl=1 1297w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?resize=595%2C289&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?resize=960%2C466&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/gpoplapsccna_11.png?resize=768%2C373&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/gpo-para-laps-con-cuenta-nativa-administrativa/feed</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16840</post-id>	</item>
		<item>
		<title>Instalar y configurar Microsoft LAPS (Local Administrator Password Solution)</title>
		<link>https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution</link>
					<comments>https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 18 Sep 2023 06:45:24 +0000</pubDate>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[LAPS]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[TIC]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16725</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo instalar y configurar Microsoft LAPS (Local Administrator Password Solution), LAPS determina si la contraseña de la cuenta del administrador local ha caducado, si la contraseña ha caducado, cambia la contraseña&#8230; <a href="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo instalar y configurar Microsoft LAPS (Local Administrator Password Solution), LAPS determina si la contraseña de la cuenta del administrador local ha caducado, si la contraseña ha caducado, cambia la contraseña del administrador local a un nuevo valor aleatorio y transmite la nueva contraseña y la fecha de caducidad a Active Directory donde se almacena en unos atributos especiales asociados con el objeto de equipo de AD. Las contraseñas se almacenan en Active Directory y están protegidas por listas de control de acceso (ACLs) por lo que solo los usuarios elegibles pueden leerlas o solicitar su restablecimiento.</p>
<ul>
<li>Lo primero que vamos a realizar será descargarnos el instalador de LAPS <a href="https://www.microsoft.com/en-us/download/details.aspx?id=46899" target="_blank" rel="noopener">desde este link</a>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?ssl=1" data-lbwps-width="1561" data-lbwps-height="625" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1-1536x615.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16726" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?fit=1561%2C625&amp;ssl=1" data-orig-size="1561,625" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?fit=640%2C256&amp;ssl=1" class="aligncenter size-full wp-image-16726" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?resize=640%2C256&#038;ssl=1" alt="" width="640" height="256" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?w=1561&amp;ssl=1 1561w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?resize=595%2C238&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?resize=960%2C384&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?resize=768%2C307&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?resize=1536%2C615&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_1.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos descargamos la versión de 64 bits:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?ssl=1" data-lbwps-width="1288" data-lbwps-height="618" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16727" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?fit=1288%2C618&amp;ssl=1" data-orig-size="1288,618" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?fit=640%2C307&amp;ssl=1" class="aligncenter size-full wp-image-16727" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?resize=640%2C307&#038;ssl=1" alt="" width="640" height="307" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?w=1288&amp;ssl=1 1288w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?resize=595%2C285&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?resize=960%2C461&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_2.png?resize=768%2C368&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí podemos ver el paquete msi descargado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?ssl=1" data-lbwps-width="1047" data-lbwps-height="267" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16728" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?fit=1047%2C267&amp;ssl=1" data-orig-size="1047,267" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?fit=640%2C163&amp;ssl=1" class="aligncenter size-full wp-image-16728" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?resize=640%2C163&#038;ssl=1" alt="" width="640" height="163" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?w=1047&amp;ssl=1 1047w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?resize=595%2C152&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?resize=960%2C245&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_3.png?resize=768%2C196&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora sobre cualquiera de nuestros controladores de dominio vamos a instalar el paquete msi LAPS.x64, siguiendo estos pasos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_4.png?ssl=1" data-lbwps-width="505" data-lbwps-height="398" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16729" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_4.png?fit=505%2C398&amp;ssl=1" data-orig-size="505,398" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_4.png?fit=505%2C398&amp;ssl=1" class="aligncenter size-full wp-image-16729" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_4.png?resize=505%2C398&#038;ssl=1" alt="" width="505" height="398" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_5.png?ssl=1" data-lbwps-width="506" data-lbwps-height="397" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16730" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_5.png?fit=506%2C397&amp;ssl=1" data-orig-size="506,397" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_5.png?fit=506%2C397&amp;ssl=1" class="aligncenter size-full wp-image-16730" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_5.png?resize=506%2C397&#038;ssl=1" alt="" width="506" height="397" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_6.png?ssl=1" data-lbwps-width="507" data-lbwps-height="398" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16731" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_6.png?fit=507%2C398&amp;ssl=1" data-orig-size="507,398" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_6.png?fit=507%2C398&amp;ssl=1" class="aligncenter size-full wp-image-16731" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_6.png?resize=507%2C398&#038;ssl=1" alt="" width="507" height="398" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_7.png?ssl=1" data-lbwps-width="501" data-lbwps-height="396" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16732" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_7.png?fit=501%2C396&amp;ssl=1" data-orig-size="501,396" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_7.png?fit=501%2C396&amp;ssl=1" class="aligncenter size-full wp-image-16732" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_7.png?resize=501%2C396&#038;ssl=1" alt="" width="501" height="396" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_8.png?ssl=1" data-lbwps-width="502" data-lbwps-height="397" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16733" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_8.png?fit=502%2C397&amp;ssl=1" data-orig-size="502,397" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_8.png?fit=502%2C397&amp;ssl=1" class="aligncenter size-full wp-image-16733" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_8.png?resize=502%2C397&#038;ssl=1" alt="" width="502" height="397" /></a></p>
<ul>
<li>Si accedemos a <strong>Panel de control &gt; Programas y características</strong> podemos ver que ya lo tenemos desplegado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?ssl=1" data-lbwps-width="1019" data-lbwps-height="400" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16734" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?fit=1019%2C400&amp;ssl=1" data-orig-size="1019,400" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?fit=640%2C251&amp;ssl=1" class="aligncenter size-full wp-image-16734" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?resize=640%2C251&#038;ssl=1" alt="" width="640" height="251" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?w=1019&amp;ssl=1 1019w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?resize=595%2C234&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?resize=960%2C377&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_9.png?resize=768%2C301&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez que se haya completado el proceso de instalación, nos habrá creado en la carpeta <strong>%systemdrive%\Windows\PolicyDefinitions </strong>la plantilla que debemos utilizar para configurar nuestra GPO para LAPS:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?ssl=1" data-lbwps-width="1631" data-lbwps-height="598" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10-1536x563.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16735" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?fit=1631%2C598&amp;ssl=1" data-orig-size="1631,598" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?fit=640%2C235&amp;ssl=1" class="aligncenter size-full wp-image-16735" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?resize=640%2C235&#038;ssl=1" alt="" width="640" height="235" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?w=1631&amp;ssl=1 1631w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?resize=595%2C218&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?resize=960%2C352&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?resize=768%2C282&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?resize=1536%2C563&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si queramos utilizarla en nuestras directivas de dominio, debemos copiar estos ficheros en sus respectivas carpetas dentro de <strong>PolicyDefinitions </strong>que tenemos dentro de <strong>SYSVOL:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?ssl=1" data-lbwps-width="849" data-lbwps-height="426" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16736" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?fit=849%2C426&amp;ssl=1" data-orig-size="849,426" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?fit=640%2C321&amp;ssl=1" class="aligncenter size-full wp-image-16736" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?resize=640%2C321&#038;ssl=1" alt="" width="640" height="321" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?w=849&amp;ssl=1 849w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?resize=595%2C299&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_11.png?resize=768%2C385&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?ssl=1" data-lbwps-width="851" data-lbwps-height="293" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16737" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?fit=851%2C293&amp;ssl=1" data-orig-size="851,293" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?fit=640%2C220&amp;ssl=1" class="aligncenter size-full wp-image-16737" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?resize=640%2C220&#038;ssl=1" alt="" width="640" height="220" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?w=851&amp;ssl=1 851w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?resize=595%2C205&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_12.png?resize=768%2C264&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Seguimos en el controlador de domino dónde hemos desplegado LAPS, y ahora vamos a importar el módulo <strong>AdmPwd.</strong><strong>ps </strong>ejecutando sobre PowerShell con permisos de administrador el comando <strong>Import-Module AdmPwd.ps</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?ssl=1" data-lbwps-width="883" data-lbwps-height="167" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16738" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?fit=883%2C167&amp;ssl=1" data-orig-size="883,167" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?fit=640%2C121&amp;ssl=1" class="aligncenter size-full wp-image-16738" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?resize=640%2C121&#038;ssl=1" alt="" width="640" height="121" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?w=883&amp;ssl=1 883w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?resize=595%2C113&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_13.png?resize=768%2C145&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Actualizamos el esquema de Active Directory con <strong>Update-AdmPwdADSchema</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?ssl=1" data-lbwps-width="888" data-lbwps-height="269" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16739" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?fit=888%2C269&amp;ssl=1" data-orig-size="888,269" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?fit=640%2C194&amp;ssl=1" class="aligncenter size-full wp-image-16739" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?resize=640%2C194&#038;ssl=1" alt="" width="640" height="194" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?w=888&amp;ssl=1 888w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?resize=595%2C180&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_14.png?resize=768%2C233&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Definimos las unidades organizativas donde queremos aplicar los permisos para la gestión de LAPS, ejecutando el siguiente comando <strong>Set-AdmPwdComputerSelfPermission -OrgUnit &lt;OU&gt;:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?ssl=1" data-lbwps-width="892" data-lbwps-height="484" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16740" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?fit=892%2C484&amp;ssl=1" data-orig-size="892,484" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?fit=640%2C347&amp;ssl=1" class="aligncenter size-full wp-image-16740" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?resize=640%2C347&#038;ssl=1" alt="" width="640" height="347" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?w=892&amp;ssl=1 892w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?resize=595%2C323&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_15.png?resize=768%2C417&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar una GPO para LAPS en Active Directory, al instalar la plantilla AdmPwd.admx de LAPS (instalación LAPS.x64) se añaden las nuevas políticas para establecer su configuración, habilitamos la política y en el caso de que el administrador local no sea el nombre por defecto (Administrator o Administrador) indicamos el nombre de la cuenta local tipo administrador que esté configurada en los equipos del dominio y los parámetros de las passwords como la complejidad, longitud y expiración:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?ssl=1" data-lbwps-width="1657" data-lbwps-height="671" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16-1536x622.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16741" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?fit=1657%2C671&amp;ssl=1" data-orig-size="1657,671" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?fit=640%2C259&amp;ssl=1" class="aligncenter size-full wp-image-16741" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?resize=640%2C259&#038;ssl=1" alt="" width="640" height="259" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?w=1657&amp;ssl=1 1657w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?resize=595%2C241&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?resize=960%2C389&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?resize=768%2C311&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?resize=1536%2C622&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez que tenemos creada la GPO la vamos a vincular sobre las unidades organizativas que indicamos anteriormente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?ssl=1" data-lbwps-width="1614" data-lbwps-height="759" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17-1536x722.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16742" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?fit=1614%2C759&amp;ssl=1" data-orig-size="1614,759" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?fit=640%2C301&amp;ssl=1" class="aligncenter size-full wp-image-16742" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?resize=640%2C301&#038;ssl=1" alt="" width="640" height="301" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?w=1614&amp;ssl=1 1614w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?resize=595%2C280&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?resize=960%2C451&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?resize=768%2C361&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?resize=1536%2C722&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con esto ya tendríamos implementado y configurado LAPS en nuestra infraestructura, y ahora para ver la password del administrador local de los equipos, accedemos a cualquiera de nuestros controladores de dominio y ejecutamos sobre PowerShell <strong>Get-AdmPwdPassword &lt;HOSTNAME&gt; | fl:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?ssl=1" data-lbwps-width="917" data-lbwps-height="272" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16743" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?fit=917%2C272&amp;ssl=1" data-orig-size="917,272" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?fit=640%2C190&amp;ssl=1" class="aligncenter size-full wp-image-16743" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?resize=640%2C190&#038;ssl=1" alt="" width="640" height="190" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?w=917&amp;ssl=1 917w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?resize=595%2C176&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_18.png?resize=768%2C228&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Desde el LAPS UI (ejecutándolo como administrador) del controlador de dominio donde instalamos LAPS también podemos ver el password:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?ssl=1" data-lbwps-width="1242" data-lbwps-height="506" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16744" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?fit=1242%2C506&amp;ssl=1" data-orig-size="1242,506" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?fit=640%2C261&amp;ssl=1" class="aligncenter size-full wp-image-16744" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?resize=640%2C261&#038;ssl=1" alt="" width="640" height="261" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?w=1242&amp;ssl=1 1242w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?resize=595%2C242&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?resize=960%2C391&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_19.png?resize=768%2C313&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>También es posible restablecer la password de administrador local de un equipo del dominio desde PowerShell, ejecutando <strong>Reset-AdmPwdPassword -ComputerName:&lt;HOSTNAME&gt;:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?ssl=1" data-lbwps-width="901" data-lbwps-height="372" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16745" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?fit=901%2C372&amp;ssl=1" data-orig-size="901,372" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?fit=640%2C264&amp;ssl=1" class="aligncenter size-full wp-image-16745" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?resize=640%2C264&#038;ssl=1" alt="" width="640" height="264" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?w=901&amp;ssl=1 901w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?resize=595%2C246&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_20.png?resize=768%2C317&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sólo los usuarios Administradores del dominio tienen permisos de lectura y escritura sobre los valores de los atributos donde se almacena la password y la fecha de expiración, en muchas ocasiones, necesitamos dar permisos a otros usuarios, por lo que vamos a crear dos grupos, uno de lectura (LAPS_R) y otro de lectura-escritura (LAPS_RW), dentro de estos grupos añadimos a los usuarios que nos interesen:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?ssl=1" data-lbwps-width="1511" data-lbwps-height="505" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16746" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?fit=1511%2C505&amp;ssl=1" data-orig-size="1511,505" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?fit=640%2C214&amp;ssl=1" class="aligncenter size-full wp-image-16746" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?resize=640%2C214&#038;ssl=1" alt="" width="640" height="214" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?w=1511&amp;ssl=1 1511w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?resize=595%2C199&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?resize=960%2C321&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?resize=768%2C257&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_21.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora asignamos los permisos para el grupo de solo lectura con el comando <strong>Set-AdmPwdReadPasswordPermission -OrgUnit &lt;OU&gt; -AllowedPrincipals &lt;Usuarios/Grupos&gt;:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?ssl=1" data-lbwps-width="877" data-lbwps-height="304" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16747" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?fit=877%2C304&amp;ssl=1" data-orig-size="877,304" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?fit=640%2C222&amp;ssl=1" class="aligncenter size-full wp-image-16747" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?resize=640%2C222&#038;ssl=1" alt="" width="640" height="222" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?w=877&amp;ssl=1 877w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?resize=595%2C206&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_22.png?resize=768%2C266&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora asignamos los permisos para el grupo de lectura-escritura con el comando <strong>Set-AdmPwdResetPasswordPermission -OrgUnit &lt;OU&gt; -AllowedPrincipals &lt;Usuarios/Grupos&gt;:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?ssl=1" data-lbwps-width="869" data-lbwps-height="287" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16748" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?fit=869%2C287&amp;ssl=1" data-orig-size="869,287" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?fit=640%2C211&amp;ssl=1" class="aligncenter size-full wp-image-16748" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?resize=640%2C211&#038;ssl=1" alt="" width="640" height="211" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?w=869&amp;ssl=1 869w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?resize=595%2C197&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_23.png?resize=768%2C254&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con el siguiente cmdlet verificamos la asignación de permisos asignados a las Unidades Organizativas, <strong>Find-AdmPwdExtendedRights -OrgUnit &lt;OU_AD&gt;</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?ssl=1" data-lbwps-width="1068" data-lbwps-height="324" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16749" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?fit=1068%2C324&amp;ssl=1" data-orig-size="1068,324" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?fit=640%2C194&amp;ssl=1" class="aligncenter size-full wp-image-16749" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?resize=640%2C194&#038;ssl=1" alt="" width="640" height="194" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?w=1068&amp;ssl=1 1068w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?resize=595%2C181&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?resize=960%2C291&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_24.png?resize=768%2C233&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En los objetos tipo «Computer» de la unidad organizativa de Active Directory donde se delegaron los permisos para LAPS podemos comprobar que se han añadido dos nuevos atributos:</li>
<li><strong>ms-Mcs-AdmPwd</strong>: Almacena la password local del equipo.</li>
<li><strong>ms-Mcs-AdmPwdExpirationTime</strong>: Tiempo en la que la password expirará y será renovada por otra password aleatoria cumpliendo los requisitos establecidos en la GPO.</li>
<li>A través del Editor de interfaces de servicios de Active Directory ADSI (adsiedit.msc) comprobamos como se han creado estos atributos y podemos ver su valor desde la pestaña de editor de atributos de la propia ficha del objeto en la consola de Active Directory:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?ssl=1" data-lbwps-width="1330" data-lbwps-height="433" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16750" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?fit=1330%2C433&amp;ssl=1" data-orig-size="1330,433" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?fit=640%2C209&amp;ssl=1" class="aligncenter size-full wp-image-16750" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?resize=640%2C208&#038;ssl=1" alt="" width="640" height="208" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?w=1330&amp;ssl=1 1330w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?resize=595%2C194&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?resize=960%2C313&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?resize=768%2C250&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_25.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?ssl=1" data-lbwps-width="949" data-lbwps-height="662" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16751" data-permalink="https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/iyclaps_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?fit=949%2C662&amp;ssl=1" data-orig-size="949,662" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="iyclaps_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?fit=640%2C446&amp;ssl=1" class="aligncenter size-full wp-image-16751" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?resize=640%2C446&#038;ssl=1" alt="" width="640" height="446" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?w=949&amp;ssl=1 949w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?resize=595%2C415&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?resize=768%2C536&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/09/iyclaps_26.png?resize=250%2C175&amp;ssl=1 250w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/instalar-y-configurar-microsoft-laps-local-administrator-password-solution/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16725</post-id>	</item>
	</channel>
</rss>
