Baseline

Entra ID Settings

Tenant-wide Entra ID settings for device registration, Windows LAPS, and self-service password reset — deployed idempotently via the deployEntraIDSettings pipeline toggle. These settings are often inconsistent across tenants when managed manually.

Device RegistrationWindows LAPSSSPREntra IDIdentity Platform

Device Registration Settings

Users may join devices to Entra ID
All users

Any licensed user can Entra-join a device. In practice, Autopilot and Intune enrollment channels are the primary join methods.

Require MFA to join / register devices
Enabled

A second factor is required at the time of Entra join. Prevents unauthorized device registration from compromised credentials alone.

Maximum devices per user
Configurable (default: 20)

Limits the number of devices a single user can register. Adjust per-tenant based on environment needs.

Enterprise State Roaming
Scoped to target groups

Windows settings and app data sync across Entra-joined devices for users in the Modern Workplace Users group.

Stale device management
Enabled

Devices inactive for 90+ days are flagged. Automated cleanup is configured where tenant size warrants it.

Windows LAPS

Windows LAPS (Local Admin Password Solution)
Enabled

Each managed Windows device gets a unique, randomly-generated local admin password escrowed to Entra ID. No shared admin passwords across devices.

Password backup directory
Entra ID

Passwords are stored in Entra ID (not on-premises AD). Admins retrieve them via the Entra portal or Graph API.

Password complexity
High — uppercase, lowercase, digits, symbols

Generated passwords use all character classes with a minimum length of 20 characters.

Password age (max)
30 days

LAPS automatically rotates the local admin password every 30 days, or immediately after use depending on post-authentication action.

Post-authentication action
Reset password + log off

After an admin authenticates using the LAPS password, Entra immediately triggers a rotation and logs off the local admin session.

Self-Service Password Reset (SSPR)

SSPR enabled for
All users

All licensed users can reset their own passwords without contacting the helpdesk — reducing support load and improving user experience.

Number of methods required to reset
2

Users must verify identity with two registered methods before resetting their password. Prevents single-method bypass.

Available reset methods
Authenticator app, Email, Phone

Users can register multiple methods. The pipeline configures which methods are available for SSPR.

SSPR registration campaign
Enabled at first sign-in

Users without SSPR registration are prompted to register at their next sign-in. Snooze is configurable.

Password writeback
Enabled where applicable

For hybrid environments with on-premises Active Directory, passwords reset via SSPR are written back immediately via Entra Connect.

Why LAPS Matters

Without LAPS

  • • All devices share the same local admin password
  • • Compromising one device exposes all others
  • • Password rarely changes — attackers have persistent access
  • • Lateral movement is trivial with a shared admin credential

With LAPS (CONFIG365 Default)

  • • Every device has a unique, unknown-to-humans local admin password
  • • Compromising one device yields no lateral movement benefit
  • • Password rotates every 30 days (or immediately after admin use)
  • • All access is audited via Entra ID sign-in logs