Local administrator accounts are indispensable for troubleshooting and recovery, but the passwords behind them can also become a serious security liability. Shared credentials, long or nonexistent rotation intervals, and inconsistent storage practices give attackers more time and opportunity to move laterally after a compromise.
Today, we’re introducing macOS Local Administrator Password Solution (LAPS) in Iru: a new Library Item that helps teams automatically generate, rotate, securely escrow, and control access to local administrator passwords on managed Mac computers.
One policy, unique credentials on every Mac
The macOS LAPS Library Item gives administrators a central place to define how local administrator credentials should be managed. Key capabilities include:
- Strong, customizable passwords. Define password requirements that align with your organization’s security standards, including length and character complexity, with the ability to import from Passcode Library items.
- Automatic rotation. Set an ongoing rotation cadence so credentials do not remain valid indefinitely.
- Rotation after access. When an authorized user retrieves a password, Iru rotates it after a defined window, reducing the useful lifetime of the credential.
- Multiple account support. Manage and rotate passwords for one or more local administrator accounts, with the ability to import from ADE Library Items.
- Secure escrow. Passwords are protected in transit and at rest using Iru’s security architecture for Library Item secrets.
- Guaranteed access. The Iru Agent ensures the newly set password works on the device and is successfully escrowed to Iru. The password shown to IT in Iru is a functioning admin password.
- Controlled retrieval. Role-based access limits password visibility to authorized users.
- Detailed audit history. Configuration changes, rotations, and retrieval events are recorded so teams can understand who accessed a password, for which device, and when.
The result is simple for administrators and powerful for security teams: every managed Mac can have a distinct local admin credential, governed by one consistent policy.
Built for the realities of macOS
macOS LAPS in Iru is implemented through the Iru Agent rather than through Apple’s SetAutoAdminPassword MDM command. That distinction matters when evaluating LAPS solutions for macOS.
Under the hood, password rotation on macOS is more than simply replacing one string with another. To preserve the account’s authorization chain, including SecureToken and Volume Ownership on Apple silicon, the operating system requires the existing credential during the change. The Iru Agent coordinates using the current and providing the newly generated credentials as part of a controlled rotation transaction leveraging native Open Directory APIs, rather than relying on a blind reset or shelling out to a command line tool.
That workflow is designed around three outcomes:
- Apply. The agent receives the scoped LAPS configuration and securely performs the requested account rotation on the device.
- Verify. It confirms whether the operation completed and reports the Library Item’s status back to Iru.
- Recover and retry. If macOS rejects the change or the device cannot complete it, the failure is reported, allowing the operation to be retried and investigated without losing visibility.
This architecture combines centralized policy with device-local execution, an important balance for a credential that must remain both highly protected and operationally useful.
Safer access when support teams need it
LAPS is not only about scheduled rotation. It also improves the moment when IT actually needs a local admin password.
Authorized users can retrieve the credential for a specific device without searching through a shared vault or asking another team for access. Iru records the retrieval, associates it with the requesting user and device, and queues up a subsequent rotation so the revealed password is automatically retired. Viewing a password more than once in Iru does not extend the rotation window.
For service desk and endpoint teams, that means faster recovery and less coordination. For security teams, it means less standing privilege, fewer shared secrets, little to no lateral movement, and a clearer chain of accountability.
Getting started
To deploy macOS LAPS, first be sure to complete the upgrade from Kandji to Iru, as macOS LAPS is only available in Iru tenants.
Then, create the Library Item in Iru, choose the local administrator account(s) to manage, configure the password and rotation settings, and assign it to the appropriate Assignment Map(s).
With macOS LAPS in Iru, local administrator access becomes temporary, device-specific, and accountable, without adding another tool or manual process for your team to manage. It extends Iru’s approach to Apple device management: powerful controls, delivered through a familiar workflow, with security and operational clarity built in.
Read the macOS LAPS documentation for configuration details and rotation settings, or book a demo to see how it fits with the rest of your Apple fleet management.
Mike Boylan, Director, Product
At Iru, Mike oversees the teams responsible for Apple and Android device management, compliance automation, and customer experiences. A former engineer turned product leader, he has over 20 years of experience in deploying and managing devices of all types, including many years at Apple as a Senior Consulting Engineer. At Apple, he led field and customer platform readiness for macOS, including speaking at numerous industry conferences and events, such as Apple’s Worldwide Developers Conference (WWDC).