Skip to content

Introducing macOS LAPS in Iru: Secure, automated local admin passwords

Mike Boylan Mike Boylan
Introducing macOS LAPS in Iru: Secure, automated local admin passwords

Local administrator accounts are indispensable for troubleshooting and recovery, but the passwords behind them can also become a serious security liability. Shared credentials, long or nonexistent rotation intervals, and inconsistent storage practices give attackers more time and opportunity to move laterally after a compromise.

Today, we’re introducing macOS Local Administrator Password Solution (LAPS) in Iru: a new Library Item that helps teams automatically generate, rotate, securely escrow, and control access to local administrator passwords on managed Mac computers.

One policy, unique credentials on every Mac

The macOS LAPS Library Item gives administrators a central place to define how local administrator credentials should be managed. Key capabilities include:

  • Strong, customizable passwords. Define password requirements that align with your organization’s security standards, including length and character complexity, with the ability to import from Passcode Library items.
  • Automatic rotation. Set an ongoing rotation cadence so credentials do not remain valid indefinitely.
  • Rotation after access. When an authorized user retrieves a password, Iru rotates it after a defined window, reducing the useful lifetime of the credential.
  • Multiple account support. Manage and rotate passwords for one or more local administrator accounts, with the ability to import from ADE Library Items.
  • Secure escrow. Passwords are protected in transit and at rest using Iru’s security architecture for Library Item secrets.
  • Guaranteed access. The Iru Agent ensures the newly set password works on the device and is successfully escrowed to Iru. The password shown to IT in Iru is a functioning admin password.
  • Controlled retrieval. Role-based access limits password visibility to authorized users.
  • Detailed audit history. Configuration changes, rotations, and retrieval events are recorded so teams can understand who accessed a password, for which device, and when.

The result is simple for administrators and powerful for security teams: every managed Mac can have a distinct local admin credential, governed by one consistent policy.

Built for the realities of macOS

macOS LAPS in Iru is implemented through the Iru Agent rather than through Apple’s SetAutoAdminPassword MDM command. That distinction matters when evaluating LAPS solutions for macOS.

Under the hood, password rotation on macOS is more than simply replacing one string with another. To preserve the account’s authorization chain, including SecureToken and Volume Ownership on Apple silicon, the operating system requires the existing credential during the change. The Iru Agent coordinates using the current and providing the newly generated credentials as part of a controlled rotation transaction leveraging native Open Directory APIs, rather than relying on a blind reset or shelling out to a command line tool.

That workflow is designed around three outcomes:

  1. Apply. The agent receives the scoped LAPS configuration and securely performs the requested account rotation on the device.
  2. Verify. It confirms whether the operation completed and reports the Library Item’s status back to Iru.
  3. Recover and retry. If macOS rejects the change or the device cannot complete it, the failure is reported, allowing the operation to be retried and investigated without losing visibility.

This architecture combines centralized policy with device-local execution, an important balance for a credential that must remain both highly protected and operationally useful.

Safer access when support teams need it

LAPS is not only about scheduled rotation. It also improves the moment when IT actually needs a local admin password.

Authorized users can retrieve the credential for a specific device without searching through a shared vault or asking another team for access. Iru records the retrieval, associates it with the requesting user and device, and queues up a subsequent rotation so the revealed password is automatically retired. Viewing a password more than once in Iru does not extend the rotation window.

For service desk and endpoint teams, that means faster recovery and less coordination. For security teams, it means less standing privilege, fewer shared secrets, little to no lateral movement, and a clearer chain of accountability.

Getting started

To deploy macOS LAPS, first be sure to complete the upgrade from Kandji to Iru, as macOS LAPS is only available in Iru tenants.

Then, create the Library Item in Iru, choose the local administrator account(s) to manage, configure the password and rotation settings, and assign it to the appropriate Assignment Map(s).

With macOS LAPS in Iru, local administrator access becomes temporary, device-specific, and accountable, without adding another tool or manual process for your team to manage. It extends Iru’s approach to Apple device management: powerful controls, delivered through a familiar workflow, with security and operational clarity built in.

Read the macOS LAPS documentation for configuration details and rotation settings, or book a demo to see how it fits with the rest of your Apple fleet management.

Mike Boylan, Director, Product
At Iru, Mike oversees the teams responsible for Apple and Android device management, compliance automation, and customer experiences. A former engineer turned product leader, he has over 20 years of experience in deploying and managing devices of all types, including many years at Apple as a Senior Consulting Engineer. At Apple, he led field and customer platform readiness for macOS, including speaking at numerous industry conferences and events, such as Apple’s Worldwide Developers Conference (WWDC).

Recent Articles

Featured image: Apple OS 27 Is Here. Iru Is Ready.
Adam Henry 8 min read

Apple OS 27 Is Here. Iru Is Ready.

Apple's OS 27 releases are available now, bringing new management capabilities across iPhone, iPad, Mac, Apple TV, and Vision.

Product News
Featured image: Remediating Windows vulnerabilities with a single tool
Matt Day 3 min read

Remediating Windows vulnerabilities with a single tool

Vulnerability Response is now available for Windows. Find, prioritize, and patch in one place, the same way you do for Mac.

Product News
Featured image: Rustbot, the macOS malware used in the latest Rust Supply Chain Attack
Cristian Molina 10 min read

Rustbot, the macOS malware used in the latest Rust Supply Chain Attack

On August 20, 2026, attackers published malicious versions of three widely used Rust packages to crates.io, the official Rust package registry. On macOS, the payload is a remote access trojan (RAT) that collects cloud credentials, SSH keys, cryptocurrency wallet data, and browser profile information, then sends it to attacker-controlled infrastructure. It installs a launch agent to survive reboots and accepts follow-on commands from its operators. Once running, it decrypts its configuration, profiles the host, Reads the local browser stores, installs persistence via LaunchAgent, and beacons out. The packages were available for approximately two hours before removal. The attackers also withdrew the previous stable versions, which pushed automated dependency resolution toward the compromised releases. Any environment that compiled an affected project during that window should be treated as compromised. This blog documents Iru's analysis of the native Apple Silicon ARM64 implant.

Threat Intelligence

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.