We’ve been testing macOS LAPS in Hexnode. Basic LAPS works for creating and managing a local administrator account through policy, but our actual requirement is to rotate the password for an existing local admin account, for example <admin_account>. The documentation mentions Advanced LAPS > Existing Admin Accounts, but that option appears to require an upgrade/add-on in our portal. Also, during testing, we noticed that when the LAPS policy is removed from a Mac, the local admin account created by that policy is removed too. Is that expected? Is there a way to keep the account on the device but stop Hexnode from rotating its password?
macOS LAPS: Managing existing admin accounts and retaining policy-created accountsSolved
Replies (5)
Yes, the behavior you observed is expected. For macOS, a local administrator account created through a Hexnode LAPS or local account policy is tied to that policy payload. When the policy is disassociated from the device, Hexnode revokes the payload, and the local admin account created by that policy is removed from the Mac.
To retain an account created by a Hexnode policy, keep the policy assigned to the device. If the goal is only to stop frequent password changes, adjust the password rotation settings instead of removing the policy. For example, set password rotation to manual or use a longer rotation interval.
For managing an already existing local admin account with password rotation, Advanced LAPS for macOS is required. The Existing Admin Accounts capability is part of Advanced LAPS and may require an add-on depending on the subscription.
So if I understand correctly, Basic LAPS is only meant for admin accounts created by the policy itself. If that policy is removed, the account goes away with it. It can’t take over an existing account that was already on the Mac?
Correct. Basic LAPS manages the local admin account that Hexnode creates through the assigned policy. Managing a native/existing local admin account on macOS requires Advanced LAPS. If you need an admin account to exist independently of the Hexnode policy lifecycle, another approach is to create the account outside the LAPS policy, such as with a custom shell script. Accounts created natively on macOS through a script are not removed when a Hexnode LAPS policy is disassociated.
We considered the script route too. If an admin account is created using a shell script from Hexnode, will Hexnode still rotate that password automatically?
No. Creating an admin account with a custom shell script and rotating its password with LAPS are separate workflows. A script-created account can persist on the Mac after policy removal because it exists as a native macOS account. However, automatic LAPS password rotation for an existing native admin account requires Advanced LAPS. If you use scripts for account creation or password changes, the script logic, validation, maintenance, and troubleshooting would need to be handled by your team. Script development and customization are outside standard support scope unless handled through a paid support or professional services engagement.