The Local Administrator Password Solution (LAPS) provides a solution to the issue of using a common local account with an identical or known password on every computer in a domain. LAPS resolves this issue by setting a different, random password for the common local administrator account on every workstation in the domain. This solution would not be pushed to the Servers but only for the domain joined workstations. Basically everything that is within the Workstations OU from Active Directory will have this solution pushed.

 

The solution will work via GPO so it can take a couple of days for it to get pushed to the workstations(installation is done upon power up). As service desk you will be granted access to look for these local admin passwords if needed. All you need, is to log in to pr-gb-mgmt-03 (10.101.3.170), open the LAPS UI program (can be searched from the windows search bar) and just search by workstation name. The password will be listed. If no password would be listed the workstation would still have the old admin password. Please find a screen shot of the LAPS UI here under: