LAPS Encryption Issues

Evan 0 Reputation points
2025-07-25T20:13:24.27+00:00

Good afternoon!

I am not sure if this is an Intune issue or an Active directory issue, but we are working towards implementing LAPS through intune and at the moment LAPS is working through AD but not through Intune. However, the LAPS passwords reset ever hour, GPUpdate, or restart of the machine. When we check the logs we get this error:

The managed account password needs to be updated due to one or more reasons (0x4200):

The policy is configured for password encryption but the encrypted password attribute was not found The password version identifier stored in Active Directory does not match the locally stored version

We've checked to make sure we have the correct group policy applied to this system and all systems both for the AD side and the Intune side. We have enabled encryption for both policies but this issue still persists. Any ideas or help would be appreciated!

Microsoft Security | Intune | Security
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Jindal 11,166 Reputation points
    2025-07-25T20:49:30.93+00:00

    Why use both? GPO is most likely taking precedence. Use cloud laps implemented through Intune only.

    #notanAIgeneratedresponse


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.