← Back to Projects
Business Systems House 2025
Enterprise Privilege Access Management (PAM) & LAPS Deployment
Windows LAPS Active Directory PAM Privilege Elevation RBAC PowerShell
Enterprise Privilege Access Management (PAM) & LAPS Deployment
Eliminated pass-the-hash attack risks by deploying Windows LAPS to continuously randomize local administrator passwords across workstation fleets.
Key Features & Implementation
- Automated Password Randomization: Configured GPO rules forcing 16-character randomized local admin passwords rotated every 30 days.
- AD-Vaulted Password Encryption: Restricted LAPS password read permissions strictly to authorized Tier-2 IT service desk personnel.
- Privilege Elevation Tracking: Configured audit alerts whenever a local administrator password was checked out from Active Directory.