Hi @luke, welcome to the Hexnode Connect community!
You are absolutely right to prioritize this. Moving away from static local admin passwords is one of the most effective steps you can take to secure your macOS fleet and prevent lateral movement in the event a device is compromised.
Basic LAPS is designed for exactly your scenario: it provides a rapid, streamlined deployment for IT admins who want immediate baseline security without configuring complex parameters. When activated, Hexnode automatically provisions a default local administrator account on your targeted Macs and handles the credential management entirely in the background.
Here is what happens behind the scenes with Basic LAPS:
How to activate it: You can deploy this in just a few clicks by editing an existing macOS policy or creating a new one:
- Navigate to Policies and select your target macOS policy.
- On the left-hand menu, go to macOS > Security > LAPS.
- Under the Basic LAPS section, click Configure.
- Select your required password complexity by checking the boxes for Uppercase letters, Lowercase letters, and Numbers.
- Go to Policy Targets, ensure your Macs are selected, and hit Save.
Whenever you or your team need to authenticate on a Mac for maintenance, simply navigate to that device’s summary page under the Manage tab. Click on Local Accounts > LAPS, and you will be able to securely view the current active password.
Hope this helps give you some peace of mind! Let us know if you have any questions during the rollout.