Hexnode has expanded its Local Administrator Password Solution (LAPS), known as Hexnode LAPS, to include macOS, complementing its existing Windows coverage. Centrally managed through the Hexnode Unified Endpoint Management (UEM) console, the solution enhances security for local administrator credentials and controls privileged access across Windows and macOS systems.
The enhancement of Hexnode LAPS reduces reliance on static credentials, isolated account setups, and directory-based access, strengthening security on a large scale. This update minimises the risk of lateral movement within networks by ensuring every device has a distinct, securely stored secret.
Automating password rotation
With the growing number of devices, static administrator passwords pose a significant threat to endpoint security, particularly when left unchanged or used on multiple devices. Hexnode LAPS mitigates this risk by automating password changes and allowing IT teams to enforce password standards consistently through centralised policies.
Unlike older LAPS solutions that require directory sync, Hexnode LAPS functions independently of directories, allowing IT staff to securely access credentials through the UEM console, even if devices are off-network, temporarily offline, or operating outside normal corporate settings.
Policy-driven automation
Hexnode LAPS addresses the operational challenge of overseeing multiple administrator accounts
Hexnode LAPS supports compliance and audit needs by enabling IT teams to set retention limits for previous passwords, achieving a balance between audit traceability and reduced exposure. By automating password security policies, it enhances compliance readiness and lessens manual workloads for IT professionals.
In addition to managing stored credentials, Hexnode LAPS addresses the operational challenge of overseeing multiple administrator accounts. Unlike traditional LAPS tools that typically rotate only the default admin account, Hexnode LAPS manages multiple local admin accounts at once, facilitating governance over any necessary contractors or specialised roles.
Organisational hardening measures
Hexnode LAPS prevents delays in onboarding for newly set up or reset devices by automatically creating required admin accounts with secure settings as soon as a policy is deployed. Governance is maintained over built-in admin accounts, even if they are renamed or disabled for organisational hardening.
To further enhance security, it enforces strict post-access measures by automatically disabling admin accounts after a set period of inactivity and initiating immediate password changes once a credential has been accessed, significantly reducing credential exposure time.
As security measures evolve to protect endpoints across various environments, Hexnode remains committed to delivering effective security solutions that combine robust credential management, operational ease, and cross-platform operability.
Hexnode announces the expansion of its Local Administrator Password Solution (LAPS), Hexnode LAPS, to macOS. Managed centrally through the Hexnode Unified Endpoint Management (UEM) console, the solution now delivers enterprise-grade local administrator credential security and privileged access safeguards across both Windows and macOS.
By eliminating the reliance on static credentials, siloed account configurations, and directory-tied access models, this expansion allows IT teams to strengthen local administrator security at scale. Furthermore, it directly mitigates the risk of lateral movement across the network by ensuring every endpoint maintains a unique, securely vaulted secret.
Automating password rotation
As device fleets grow, static administrator passwords become a critical vulnerability in endpoint security—especially when left unchanged for long periods or reused across devices.
Hexnode LAPS addresses this risk by automating password rotation and enabling IT teams to apply password standards fleet-wide through centralised policies. Unlike legacy LAPS tools that rely heavily on directory synchronisation, Hexnode LAPS is completely directory-independent. This ensures authorised IT administrators can securely retrieve credentials directly from the UEM console, even when devices are off-domain, temporarily disconnected, or operating outside standard corporate setups.
Policy-driven automation
To support compliance and audit efforts, Hexnode LAPS helps IT teams define the exact retention count for previous passwords, balancing the need for audit traceability with the principle of least exposure. By turning password security into policy-driven automation, Hexnode LAPS strengthens compliance readiness while significantly reducing the manual burden on IT.
Beyond merely vaulting credentials, IT admins face the operational challenge of governing the fragmented administrator accounts themselves. While traditional LAPS tools often rotate only the single, default admin account, Hexnode LAPS supports multiple local administrator accounts simultaneously—bringing every necessary contractor, or specialised role under automated governance.
Organisational hardening measures
To prevent onboarding delays on freshly provisioned or reset devices, Hexnode LAPS can automatically create missing admin accounts with secure configurations the moment a policy is deployed. Additionally, it maintains governance over built-in administrator accounts, even if they have been renamed or temporarily disabled as part of organisational hardening measures.
To further lock down this workflow, the solution enforces strict post-access controls. It can automatically disable administrator accounts after a specified period of inactivity and trigger an immediate password cycling right after a credential has been viewed, drastically limiting the window of credential exposure.
As organisations continue to strengthen endpoint security across diverse environments, Hexnode remains focused on delivering practical security capabilities that combine secure credential controls, operational simplicity, and cross-platform support.