Check the Administrator account on all devices (LAPS)

Hmmm you're going at this the wrong way. 1. Enable local admin account via GPO 2. Use LAPS to control it's password 3. Create a domain group for workstation administration 4. Assign this group to the local administrators group on workstations via GPO 5. Each tech/admin needs at least 2 accounts. One as standard user, the other with delegated privileges on desktops. 6. Add this second account to the workstation admins group from step 3

The LAPS password is last resort/breakglass. You cannot audit who did what what this account so it should almost never use it.

Same goes for servers admins. You don't need domain admin rights to manage servers. Least privilege principle is your friend :)

/r/PowerShell Thread Parent