Hexnode has expanded its Local Administrator Password Solution (LAPS), known as Hexnode LAPS, to now cover macOS systems.
The solution, which is centrally managed through the Hexnode Unified Endpoint Management (UEM) console, enhances security by offering robust local administrator credential protection and privileged access management across both Windows and macOS platforms.
Reducing Static Credential Dependence
This expansion addresses a critical security need by eliminating static credentials, isolated account configurations, and directory-tied access models. It enables IT teams to bolster local administrator security on a wide scale, mitigating risks of lateral network movement by ensuring each endpoint possesses a unique, securely stored password.
Automated Password Rotation
This expansion addresses a critical security need by eliminating static credentials
With the increasing size of device fleets, static administrator passwords are a significant vulnerability, especially when they remain unchanged over time or are reused. Hexnode LAPS mitigates this risk through automated password rotation, allowing IT teams to enforce password standards across all devices via centralized policies.
Unlike older LAPS tools dependent on directory synchronization, Hexnode LAPS operates independently of directories, allowing IT administrators to retrieve credentials securely from the UEM console even if devices are off-domain or in non-standard operating conditions.
Policy-Driven Automation for Compliance
Hexnode LAPS assists IT teams in supporting compliance and audit activities by enabling them to specify the retention count for previous passwords.
This balances the need for audit traceability with limited exposure. The policy-driven automation enhances compliance readiness while reducing the manual workload on IT departments. Unlike traditional LAPS tools that focus on rotating a single default admin account, Hexnode LAPS supports governance of multiple local administrator accounts, covering all necessary roles including contractors and specialized roles.
Streamlined Operations and Organizational Hardening
To prevent delays during device provisioning or resets, Hexnode LAPS can automatically create missing admin accounts with secure settings upon policy deployment. The solution maintains control over built-in administrator accounts regardless of renaming or temporary disabling, as part of organizational hardening strategies. Additionally, it enforces strict post-access controls by automatically disabling admin accounts after inactivity and promptly initiating password cycling post-credential access, thus minimizing credential exposure.
With this expansion, Hexnode aims to provide enhanced endpoint security that aligns practical security capabilities with simplified operations and cross-platform support, as organizations continue to fortify their security postures across varied environments.
Hexnode announces the expansion of its Local Administrator Password Solution (LAPS), Hexnode LAPS, to macOS. Managed centrally through the Hexnode Unified Endpoint Management (UEM) console, the solution now delivers enterprise-grade local administrator credential security and privileged access safeguards across both Windows and macOS.
By eliminating the reliance on static credentials, siloed account configurations, and directory-tied access models, this expansion allows IT teams to strengthen local administrator security at scale. Furthermore, it directly mitigates the risk of lateral movement across the network by ensuring every endpoint maintains a unique, securely vaulted secret.
Automating password rotation
As device fleets grow, static administrator passwords become a critical vulnerability in endpoint security—especially when left unchanged for long periods or reused across devices.
Hexnode LAPS addresses this risk by automating password rotation and enabling IT teams to apply password standards fleet-wide through centralized policies. Unlike legacy LAPS tools that rely heavily on directory synchronization, Hexnode LAPS is completely directory-independent. This ensures authorized IT administrators can securely retrieve credentials directly from the UEM console, even when devices are off-domain, temporarily disconnected, or operating outside standard corporate setups.
Policy-driven automation
To support compliance and audit efforts, Hexnode LAPS helps IT teams define the exact retention count for previous passwords, balancing the need for audit traceability with the principle of least exposure. By turning password security into policy-driven automation, Hexnode LAPS strengthens compliance readiness while significantly reducing the manual burden on IT.
Beyond merely vaulting credentials, IT admins face the operational challenge of governing the fragmented administrator accounts themselves. While traditional LAPS tools often rotate only the single, default admin account, Hexnode LAPS supports multiple local administrator accounts simultaneously—bringing every necessary contractor, or specialized role under automated governance.
Organizational hardening measures
To prevent onboarding delays on freshly provisioned or reset devices, Hexnode LAPS can automatically create missing admin accounts with secure configurations the moment a policy is deployed. Additionally, it maintains governance over built-in administrator accounts, even if they have been renamed or temporarily disabled as part of organizational hardening measures.
To further lock down this workflow, the solution enforces strict post-access controls. It can automatically disable administrator accounts after a specified period of inactivity and trigger an immediate password cycling right after a credential has been viewed, drastically limiting the window of credential exposure.
As organizations continue to strengthen endpoint security across diverse environments, Hexnode remains focused on delivering practical security capabilities that combine secure credential controls, operational simplicity, and cross-platform support.