We rotate our laps passwords every 30 days across the board. It’s a good middle ground—not too frequent to be annoying, but often enough to limit exposure if something goes sideways.
For servers, we bump it to every 2 weeks since they’re higher value targets. Workstations? Monthly is fine unless there’s a specific threat.
Also, check out Microsoft’s LAPS docs if you haven’t already. They’ve got some solid baseline recs.
Ever had a leak? Nah, but we audit access like crazy just in case.
For servers, we bump it to every 2 weeks since they’re higher value targets. Workstations? Monthly is fine unless there’s a specific threat.
Also, check out Microsoft’s LAPS docs if you haven’t already. They’ve got some solid baseline recs.
Ever had a leak? Nah, but we audit access like crazy just in case.
