مايكروسوفت LAPS

من أكبر التحديات التي تواجه فريق مدراء الأنظمة أو فريق الحماية هي إدارة كلمات المرور، فكلمة المرور الموحدة لجميع الأجهزة تشكل خطر كبير على الشبكة و الأنظمة.

ولنفترض بأنك مسؤول عن ١٠٠٠ جهاز وتم إختراق جهاز واحد فقط ومعرفة كلمة المرور الخاصة لحساب الأدمن المحلي لهذا الجهاز، بذلك يستطيع المخترق من الوصول لباقي ال٩٩٩ جهاز بكل سهولة لأن كلمة المرور موحدة.

 آداة LAPS  إختصار Local Administrator Password Solution و هي أداة مجانية من مايكروسوفت تساعد في إدارة كلمات المرور لأجهزة الكمبيوتر في الشركات أو القطاعات الحكومية بحيث تقوم بتوليد كلمات مرور معقدة جداً لكل جهاز و وبشكل تلقائي.

متطلبات الآداة:

  • Active Directory 2003 SP1  أو أعلى
  • Windows Server 2003 SP2  أو أعلى
  • NET Framework 4.0 
  • PowerShell 2.0  أو أعلى
  • لديك صلاحية Schema Admin

سأشرح طريقة إعداد الآداة خطوة بخطوة ولكن قبل أن تبدأ بتطبيقها على بيئة حقيقة تأكد من أخذ نسخة إحتياطية لل Active Directory وطبقها في بيئة تجريبية أولاً.

 ١- قم بتحميل آداة  LAPS من هنا على أحد السيرفرات الخاصة بالإدارة

https://www.microsoft.com/en-us/download/details.aspx?id=46899

Choose the download you want 
File Name 
LAPS*64.msi 
LAPS.x86.msi 
LAPS_Datasheet,docx 
LAPS_OperationsGuide-docx 
LAPS_TechnicalSpecification.docx 
Size 
996 KB 
968 KB 
102 KB 
644 KB 
71 KB 
Download Summary: 
KBMBGB 
1. LAPSx64.msi 
Total Size: 996 KB 
Next

  ٢- تأكد بأن لديك صلاحي ال  Schema Admins

Active Directory Users and 
File Acton View Help 
Active Directory Userç and 
> ZI Swed 
mos.Jocal 
Builtin 
Computers 
Domain Controllcrs 
ForeignSecurityPrin 
Adrnintstratcr Properties 
Ferncte cortml 
General Address 
Mertoer Of 
Me•nbe cf. 
Doman Admire 
Donan users 
Enterprise Admirts 
Poicy Cm. 
Schema Admins 
Remote Deskop Serv•ceg Profile 
A2tmrt Rmfie Telephmes 
Envrcnnent 
Active Directory Domain Serv•icee Fdder 
moz -local'Euftin 
mos local'Users 
mos JocalfUsers 
mos bcal/l-lsers 
mos local 'I-lscr: 
mos local/Users 
group Dornah 
There in no neeci to change Primary group 
Set Primary Gmup 
ycu have Maerttosh cr 
appicatons 
Hep

     ٣- قم الآن بتنصيب آداة  LAPS

Recycle Bin 
VVtndows Installer 
Preparngtc Install . 
Cancel 
Windows
Local Administrator Password Solution Setup 
Custom Setup 
Select the way you want feaWres to be installed. 
Click the icons in the tree below to change frie way features will be installed. 
x 
AdmPwd GPO Extension 
Management Tools 
Fat client IJI 
• PowerShell module 
GPO Editor templates 
Installs ADMX templates for GPO 
editor. Typically need to be installed 
on machine where GPOs are edited 
This feature requires 8KB on your 
hard drive. 
Next

٤- إفتح الPowerShell كأدمن ثم قم بكتابة الأمرين التاليين:

Import-module AdmPwd.PS

Update-AdmPwdADSchema

Administrator: Windows PowerShell 
PS C : Import-M u 1 e 
PW . ps 
PS C:\> Update-AdmPwdADSchema 
x 
peration 
ddSchemaAttri but e 
ddSchemaAttribute 
odifySchemaC1ass 
PS 
Disti nguishedName 
cn=ms-Mcs -AdmPwdExpi r ati onTime , CN=Schema , CN=Confi gur ati on , DC—m... 
cn=ms -Mcs -AdmPwd , C N=Schema , CN=Confi gur at i on , X=mos , ocal 
, CN=Schema , CN=Confi gur ati on , DC—mos , DC—I ocal 
Status 
Success 
Success 
Success

٥- إفتح آداة الGroupPolicy وتأكد بأنه قد تم إنشاء مجلد باسم  LAPS

Recenåy added 
LAPS UI 
Most used 
snipping Tool 
Paint 
Command Prompt 
Group Policy 
ment 
Windows Server 
Server Manager 
Windows 
Administrativ.„ 
Remote 
Deskto . 
Windows 
PowerSheII 
Task Manager 
Event Viewer 
Windows 
PowerSheIl ISE 
Control Panel 
File Ex lorer 
o 
New 
Oracle VM VirtualBox Guest A.„ v 
New
Adds 
Group Policy Management 
odi 
Forest: mos.local 
v Domains 
mos.local 
Default D 
> Domain 
> Group P 
> WMI Filte 
> Starter G 
> Sites 
Group Policy M 
Group Policy R 
Default Domain Policy 
Scope Details Settings Delegation 
I-irks 
link-e in thie 
Enforced 
Link Enabled 
Save Report... 
View 
New Window from Here 
Delete 
Rename 
Refresh 
Help 
WMI Filtering 
mos local 
us are linked to this GPC 
No 
pply to the following
Default Domain Policy [DCOI.M 
v Computer Configuration 
Policies 
Software Settings 
> Windows Settings 
v Administrative Temp 
> Control Panel 
N ork 
Printers 
Server 
Start Menu and T 
> System 
> Windows Compc 
All Settings 
Preferences

٦-  الأن عن طريق PowerShell قم بكتابة الأوامر التالية، علماً بأني قد أنشأت مسبقاً  OU باسم Domain Computers  ووضعت بداخلها جميع أجهزة ال Domain وقمت بإنشاء OU  باسم Groups ووضعت داخلها مجموعة باسم HelpDesk

 فمن خلال هذه الأوامر ستسمح لمجموعة الHelpDesk بقراءة كلمات المرور الخاصة بالLaps وإعادة تعينها

PS Set-AdmPwdComputerSeIfPermission 
Name 
Domain Computers 
Di sti ngui shedName 
OU=Domai Computers , 
-OrgLInit 
DC-mos , DC 
' domain computers 
—local 
PS Find—AdmPwdExtendedRights -Identity 'domain computers ' 
Obj ectDN 
OU=Domain Computers, DC—mos , DC—local 
ExtendedRightH01ders 
{NT AUTHORITY\SYSTEM , 
Status 
Del egated 
MOS\Domain Admins}
Administrator: Windows PowerShell 
PS C: 
PS Set-AdmPwdReadPasswordPermi ssion 
-Orgunit 
x 
Name 
groups 
PS 
Di sti ngui shedName 
OU=groups , DC—mos , DC—I ocal 
ou=groups , dc=mos , dc=local' -Al lowedPrincipa1s 
helpdesk 
Status 
Del egated

٧- الان قم بإنشاء مجلد على السيرفر ونقل الآداة الى المجلد بعد ذلك قم بمشاركة هذا المجلد حتى نقوم بتنصيب أداة الLAPS على أجهزة الدومين بشكل تلقائي

Pin to Quick 
access 
copy patn 
Copy Paste 
Move Copy Delete Renarm 
Paste shortcut to 
Clipboard 
This PC Local Disk (C:) Laps 
Organize 
* Quick access 
Desktop 
Downloads 
Documents 
Pictures 
a This PC 
Desktop 
Documents 
Downloads 
Music 
Pictures 
Videos 
Name 
BJ LAPSx64
Pin to Quick 
access 
copy patn 
Copy Paste 
Move 
Paste shortcut to 
Clipboard 
This PC Local Disk 
Copy Delete 
Organize 
Rename 
New 
folder 
New 
Properties 
Open 
select none 
Ou Invert selection 
Select 
Search Local Disk (C:) 
1 
Name 
Laps 
New folder 
PerfLogs 
Program Files 
Program Files 
Windows 
> 
Type 
File folder 
File folder 
Stop sharing 
Specific eople... 
File folder 
File folder 
Size 
* Quick access 
Desktop 
Downloads 
Documents 
Pictures 
This pc 
Desktop 
Documents 
Downloads 
Music 
Pictures 
Videos 
Local Disk (C:) 
Open in new window 
Pin to Quick access 
Scan with Windows Defender.„ 
Share with 
Restore previous versions 
Include in library 
Pin to Start 
Send to 
Cut 
Copy 
Paste 
Create shortcut 
Delete

'in to Quick C 
access 
* Quick ac 
Deskto 
Downl 
Docum 
Pictur 
This pc 
Deskto 
Docum 
Downl 
Music 
Pictur 
Videos 
Local D 
Select Users or Groups 
Multiple Names Found 
More than one object matched the name "domain c". Selec:t one or more 
names from this list , or, reenterthe name. 
Matching names: 
Name 
Domain Comp.. 
Domain Contr. 
Logon Name 6r. 
Domain Computers 
Domain Controllers 
E-Mail Address 
Description 
Al wo«ations 
Al domain contro 
x 
In Folder 
mos .10cal/lJsers 
mos -local / I-Isers
File Sharing 
Choose people on your network to share with 
Type a name and then click Add, or click the arrow to find someone. 
Name 
g Administrator 
Administrators 
Domain Computers 
I'm having trouble sharing 
Permission Level 
Read/Write 
Owner 
Read 
re 
Cancel
File Sharing 
Your folder is shared. 
You can maiÉ someone links to these shared items, or and paste the links into another program. 
Individual Items 
Laps 
Show me all the network shares on this computer.

٨- الان عن طريق GroupPolicy  قم بإنشاء Policy جديدة باسم Deploy LAPS وفعلها على الOU الخاصة بالأجهزة كي يتم تنصيب الأداة على الأجهزة بشكل تلقائي

Group Policy Management 
v Forest: mos,local 
Domains 
mos.local 
Default Domain 
Deploy 
> Group Policy Ok 
> WMI Filters 
> Starter GPOs 
> Sites 
Group Policy Modeling 
Group Policy Results 
Deploy Laps 
Scope Settings Delegation 
I-irks 
Display links in this location: 
mos local 
The following sites. domains, and OUS are to this GPO: 
Location 
mos -local 
Sect.rity 
Erforced 
No 
Link Enable 
Yes 
The settings in this GPO can only apply to the following groups, users, and compu 
Name 
@Authenticated Users 
Add.. 
Rernove 
Properties
Deploy Laps [DCOI.MOSLOCAI 
Computer Configuration 
Policies 
v Software Settings 
Software installat 
Windows Settings 
Administrative Temp 
Preferences 
•A User Configuration 
> Policies 
Preferences 
Name 
New 
Paste 
Refresh 
View 
Version Deployment st... Source 
The nn items tnshmnein this view, 
Package... 
Arrange Icons 
Line up Icons 
Properties 
Help
Pin to Quick 
access 
copy patn 
Copy Paste 
Move Copy Delete Renarm 
Paste shortcut to 
Clipboard 
This PC Local Disk (C:) Laps 
Organize 
* Quick access 
Desktop 
Downloads 
Documents 
Pictures 
a This PC 
Desktop 
Documents 
Downloads 
Music 
Pictures 
Videos 
Name 
BJ LAPSx64
Group Policy Management Editor 
File Action View Help 
Deploy Laps IDCOI.MOS.LOCAI 
v Computer Configuration 
PollZies 
Software Settings 
SOftware installat 
Windows Settings 
Administrative Temp 
Preferences 
User Configuration 
> Policies 
Preferences 
Name 
Deploy Software 
Server2-2016 [Running] 
Version Deployment st... Source 
There are no items to show in this view. 
x 
Select deploymert method 
@Assigned 
C) Advanced 
Select option to Assign the application wthod rnodflcations 
OK 
P 
e 
6:26 AM 
6/5/2019

٩- الان قم بإعطاء صلاحية القراءة ل Domain Computers

Group Policy Management Editor 
File Action View Help 
Deploy Laps (DCOI .MOS.LOCAI 
v Computer Configuration 
Policies 
Software Settings 
SOftware installat 
> Windows Settings 
Administrative Tern 
User Configuration 
) Policies 
Preferences 
x 
Name 
Local Admin-q 
Version 
Auto-Install 
Assign 
Publish 
All Tasks 
Refresh 
Help 
Deployment st... 
Source 
LAPS.xEA.msi 
Opens the properties dialog box for the current selection. 
631 AM 
6/5/2019
serverZ-Z01ö IHunnvngJ 
Group Policy Management Editor 
File Action View Help 
I Local Administrator Password Solution Properties 
Deploy Laps . MOS.LOCA Gener-d I-wades Cdegories Modficdions Secuty 
v Computer Configuration 
v Policies 
Software Settings 
SOftware insta 
> Windows Settings 
Administrattve Tern 
Preferences 
User Configuration 
) Policies 
Preferences 
Group or user narnes: 
CREATOR OWNER 
Anhe-tcated Users 
SYSTEM 
DorrÄn Ah-ins (MOS\Dornain Adnns) 
Enterpnse (MOS\Eterprise 
ENTERPRISE DOMAIN CONTROLLERS 
Pemissions for CREATOR OWNER 
FLAI corårol 
Specid pennssions 
For special permissions or advanced settings. cick 
Advanced. 
OK 
Row 
Deny
serverZ-Z01ö IHunnvngJ 
Group Policy Management Editor 
File Action View Help 
7 
Deploy Laps [DCOI .MOS.LOCA Gener-d I-Wades Categories Modficdions Secuty 
v Computer Configuration 
v Policies 
Software Setti 
Software 
> Windows Setti 
Administrative 
Preferences 
User Configuration 
) Policies 
Zl Preferences 
Group or user narnes: 
CREATOR OWNER 
Select Users, Computers, Service Accounts, or Groups 
Select t?is object tpe: 
hom ths loc*ion• 
filter the objed runes to select 
Dorr—n Corrvuters 
r speci permissions or 
Advanced. 
OK 
x 
x 
Types 
Check Nd•nes
Server 2-2016 [Running] 
Group Policy Management Editor 
File Action View Help 
I Local Administrator Password Solution Properties 
Deploy Laps .MOS.LOCA General Deployrnent I-wades Cdegories Modflcdions Secuty 
v Computer Configuration 
v Policies 
Software Settings 
SOftware insta 
> Windows Settings 
Administrative Tern 
Preferences 
User Configuration 
) Policies 
Preferences 
Group or user narnes: 
S' CREATOR OWNER 
AJtherticated Users 
SYSTEM 
Dornån Ah-ins (MOSIDornain Adrnns) 
Dorn*' Compuers (IOS\Domain 
Enterpnse Admins (MOS\Erterpnse .Admns) 
Pemissions for Domain Compliers 
FLAI cornrol 
Wrte 
Specid pennssions 
For speci al permissions or advanced settings• dick 
Advanced. 
Row 
Deny 
AM 
6/5/2019 
U L ef

١٠- تأكد بأن الآداة نزلت علي أجهزة المستخدمين

Programs and F 
•t• Control Pane/ All Control Panel hems Programs and Features 
uninstall or change a program 
TO uninstall a program. select it from the Est and then click Uninst•u Change. or Repair. 
View updates 
Turn Windows features on Of 
a program the 
Organize UninstaU Change 
Local Administrator 
Windows 
Windows O Update Assistant 
Publisher 
Microsoft 
Microsoft 
Microsoft on 
Installed On 
6.'5'2019 
5/22/2019 
922/2019 
5,'23/2019 
Size

ملاحظة: تستطيع تطبيق أمر  GPupdate /force إذا أردت أن تسرع الموضوع

١١- الان قم بتطبيق Policy  باسم Laps Policy على الOU الخاصة ب Domain Computers

Group Policy Management Editor 
File Group Policy Management 
File Action View Window Help 
Group Policy Management 
v mos.local 
Domains 
mos.local 
Default Domain 
Deploy Laps 
> Dorn.-;— 
Domain Computers 
[Ned Grotv Policy 
Order 
Group Poicy Deegation 
GPO 
Deploy Laps 
Eriorced 
NO 
Link 
> Dom. 
> grou 
Grou 
> WMI 
> Start 
> Sites 
Group Poli 
Group Peli 
e a GPO in this domain, and Link it here.„ 
Li n Existing 
Block Inheritance 
Group Policy Update... 
Group Policy Modeling Wizard... 
New Organizational Unit 
View 
New Window from Here 
Delete 
Rename 
Refresh 
Properties
Group Policy Management Editor 
File Group Policy Management 
File Action View Window Help 
Group Policy Management Domain Computers 
v Forest: mos.local 
[Ned Grotv Policy 
Group Poicy 
GPO 
Deegation 
Eriorced 
NO 
5 
GPO Status 
Domains 
v mos.local 
Default Domain 
Deploy Laps New GPO 
> LÄl Domain 
> Domain 
groups 
Order 
I-ilk Enabled 
x 
I-ms Pobcy 
> Group Policy O 
> Filters Source Starter GPO. 
> Starter GPOs 
60ne) 
> Sites 
Group Policy Modelin 
Group Policy Results 
7 items 1 item selected
Group Policy Management Editor 
File Action View Help 
Laps Policy [DCOI.MOS.LOCAL 
v Computer Configuration 
Policies 
> Software Settings 
> Windows Settings 
Administrative Tem 
> Control Panel 
LAPS 
> Network 
Printers 
Sen.•er 
Start Menu and 
System 
> Windows Comp 
All Settings 
Preferences 
User ration 
Policies 
Preferences 
Select an item to view its description. 
Setting 
Password Settlngs 
Name of administrator account to manage 
Do not allow password expiration time longer than required 
Enable local admin password nagement 
State 
Not configurec 
Not configurec 
Not configurec 
Not configurec
Server2-2016 [Running] 
Enable local admin password management 
Enable local admin password management 
Previous Setting 
x 
Comment: 
C.) Not Configured 
@ Enabled 
O Disabled 
Supported on: 
Options: 
At least Microsoft Windows Vista or Windows Server 2003 family 
Help: 
Enables management of password for local administrator account 
If you enable this setting. local administrator password is managed 
f you disable or not configure this setting local administrator password is NOT 
managed 
Oncel

١٢- الأن قم بفتح أداة  LAPS UI  لمشاهدة كلمة المرور الخاصة بأي جهاز 

Recendy •d&d 
Most used 
o 
Windows Server 
Windows 
ManaF 'owerSheu 
Tool 
Command Prompt 
Orxk VM VirtualB« v 
New 
Serær Manager 
Windows 
ministrat- 
Remote 
Task Manage 
t Vievær 
Windows 
ISE 
.Control 
File
Recycle Bin 
i73 
P 
[APS UI 
NEN expr*on time 
e 
n 
x

وبذلك نكون قد انتهينا من الإعدادات 🙂

اترك تعليقًا

إملأ الحقول أدناه بالمعلومات المناسبة أو إضغط على إحدى الأيقونات لتسجيل الدخول:

شعار ووردبريس.كوم

أنت تعلق بإستخدام حساب WordPress.com. تسجيل خروج   /  تغيير )

Facebook photo

أنت تعلق بإستخدام حساب Facebook. تسجيل خروج   /  تغيير )

Connecting to %s