Intune: Retrieving Admin LAPS Password for MacOS (ETS Internal)

Summary

How to look up Admin Password for Intune Managed MacOS devices at USNH.

Note: All Macs we have currently will be Intune Migrated. Any new Macs ordered will be ADE Enrolled. 

 

How-To

Task: Look up if MacOS device in Intune is ADE Enrolled or Migrated

Instructions

Step 1 - PIM role to Cloud Device Manager in Entra

Step 2 - Log into Intune 

Step 3 - Select the Device

Step 4 - Go to Hardware

Step 5 - Look under Enrollment profile

  • If there is information in the Enrollment profile, then the device is ADE Enrolled
  • If the Enrollment profile is empty, then the device is Intune Migrated

Back to top

 

Task: Retrieve Admin Password for ADE Enrolled MacOS devices

Instructions

Step 1 - PIM role to Cloud Device Manager in Entra

Step 2 - Log into Intune

Step 3 - Select Device

Step 4 - Click Passwords and Keys

Step 5 - Click Show Local admin password

  • Username is “admin” 
  • Password is case sensitive and both zero - 0 and capital o - O are used 
  • Password Rotates automatically.

Back to top

 

Task: Retrieve Admin Password for Intune Migrated MacOS devices

Instructions

Step 1 - PIM role to Cloud Device Manager in Entra

Step 2 - Log into Intune

Step 3 - Got to Devices > MacOS 

Step 4 - Click Custom attributes for MacOS under Organize devices section

Intune macOS devices showing "Custom attributes for macOS" on the left in the "Organize Devices" section.

 

Step 5 - Click on “LAPS- Migrated Devices Only

Step 6 - Click Device status

Step 7 - Find the computer and expand the “Result” section and

Step 8 - The Admin password is found in the Result section, between ><

  • Username is “admin” 
  • Password is case sensitive and both zero - 0 and capital o - O are used 
  • Password Rotates every 180 days.

Back to top

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.