๐ Secure Bits ๐ก
How do you manage ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐ ๐ณ๐ผ๐ฟ ๐๐ผ๐๐ฟ ๐น๐ผ๐ฐ๐ฎ๐น ๐ฎ๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ accounts?
Are they the ๐๐ฎ๐บ๐ฒ ๐ฒ๐๐ฒ๐ฟ๐๐๐ต๐ฒ๐ฟ๐ฒ?
Stored in a text file or ๐๐
๐ฐ๐ฒ๐น ๐๐ต๐ฒ๐ฒ๐?
Letโs be honest โ there are better (๐ฎ๐ป๐ฑ ๐๐ฎ๐ณ๐ฒ๐ฟ) ways to handle this.
If youโre running ๐ผ๐น๐ฑ๐ฒ๐ฟ ๐๐ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ท๐ผ๐ถ๐ป๐ฒ๐ฑ ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐๐๐๐๐ฒ๐บ๐, you could be using ๐๐ฒ๐ด๐ฎ๐ฐ๐ ๐๐๐ฃ๐ฆ (Local Administrator Password Solution) from Microsoft:
โ๏ธ Automatically rotates local admin passwords
โ๏ธ Stores them in Active Directory
๐ธ Protected just with ACL, can be intercepted in the network
โ๏ธ Requires schema extension + AD permissions
โ๏ธ Simple PowerShell + client-side install
๐ก ๐๐ผ๐ ๐ป๐ฒ๐๐ฒ๐ฟ ๐๐๐๐๐ฒ๐บ๐?
Then meet the New LAPS โ built into Windows 10+ and Windows Server 2019+ (at least April 2023 update).
No extra client needed. Just a schema update, permissions, and PowerShell.
๐๐ฒ๐ป๐ฒ๐ณ๐ถ๐๐ ๐ถ๐ป๐ฐ๐น๐๐ฑ๐ฒ:
โ๏ธ Encrypted password storage in AD
โ๏ธ Azure AD backup support
โ๏ธ Password history
โ๏ธ Post-authentication actions (e.g., force logoff)
โ๏ธ Custom password complexity (omit special chars, etc.)
๐ก ๐ ๐ผ๐ฟ๐ฒ ๐ฐ๐ผ๐บ๐ฝ๐น๐ฒ๐
๐ฒ๐ป๐๐ถ๐ฟ๐ผ๐ป๐บ๐ฒ๐ป๐๐?
Letโs say you manage multiple OS platforms (Windows, macOS, Linux) or multiple local accounts โ then youโll likely need something more advanced.
Recently, I spoke with Sanjay Jadvani from Synergix Labs about their solution SEVA.
Think of it as lightweight PAM โ packed with features but without the bulk.
๐ฆ๐๐ฉ๐ ๐๐ถ๐ด๐ต๐น๐ถ๐ด๐ต๐๐:
โ๏ธ Password rotation for local accounts across Windows, Unix, and macOS
โ๏ธ Open API
๐นIntegrate with ServiceNOW and other ITSM platforms
โ๏ธ Role-Based Access Control (RBAC)
๐น Even supports Tiering Model
๐น Conditional Access available
โ๏ธ Centralized management console
โ๏ธ Flexible integrations (IdP agnostic)
๐จ No matter your size or complexity โ ๐๐ผ๐ ๐ป๐ฒ๐ฒ๐ฑ ๐๐ผ๐บ๐ฒ๐๐ต๐ถ๐ป๐ด to manage local account passwords. They exist by default across all systems, and shared passwords are a lateral movement jackpot for attackers.
๐ฌ What are you using today to manage local admin passwords in your environment?
