Entra ID Settings
Tenant-wide Entra ID settings for device registration, Windows LAPS, and self-service password reset — deployed
idempotently via the deployEntraIDSettings pipeline toggle.
These settings are often inconsistent across tenants when managed manually.
Device Registration Settings
All users Any licensed user can Entra-join a device. In practice, Autopilot and Intune enrollment channels are the primary join methods.
Enabled A second factor is required at the time of Entra join. Prevents unauthorized device registration from compromised credentials alone.
Configurable (default: 20) Limits the number of devices a single user can register. Adjust per-tenant based on environment needs.
Scoped to target groups Windows settings and app data sync across Entra-joined devices for users in the Modern Workplace Users group.
Enabled Devices inactive for 90+ days are flagged. Automated cleanup is configured where tenant size warrants it.
Windows LAPS
Enabled Each managed Windows device gets a unique, randomly-generated local admin password escrowed to Entra ID. No shared admin passwords across devices.
Entra ID Passwords are stored in Entra ID (not on-premises AD). Admins retrieve them via the Entra portal or Graph API.
High — uppercase, lowercase, digits, symbols Generated passwords use all character classes with a minimum length of 20 characters.
30 days LAPS automatically rotates the local admin password every 30 days, or immediately after use depending on post-authentication action.
Reset password + log off After an admin authenticates using the LAPS password, Entra immediately triggers a rotation and logs off the local admin session.
Self-Service Password Reset (SSPR)
All users All licensed users can reset their own passwords without contacting the helpdesk — reducing support load and improving user experience.
2 Users must verify identity with two registered methods before resetting their password. Prevents single-method bypass.
Authenticator app, Email, Phone Users can register multiple methods. The pipeline configures which methods are available for SSPR.
Enabled at first sign-in Users without SSPR registration are prompted to register at their next sign-in. Snooze is configurable.
Enabled where applicable For hybrid environments with on-premises Active Directory, passwords reset via SSPR are written back immediately via Entra Connect.
Why LAPS Matters
Without LAPS
- • All devices share the same local admin password
- • Compromising one device exposes all others
- • Password rarely changes — attackers have persistent access
- • Lateral movement is trivial with a shared admin credential
With LAPS (CONFIG365 Default)
- • Every device has a unique, unknown-to-humans local admin password
- • Compromising one device yields no lateral movement benefit
- • Password rotates every 30 days (or immediately after admin use)
- • All access is audited via Entra ID sign-in logs