I'm taking a run at Microsoft’s Local Administrator Password Solution (LAPS) https://www.microsoft.com/en-us/download/details.aspx?id=46899
I am wondering, if I implement LAPS isn't it's effectiveness going to be hindered by having the ccm network account located in the local admin group on all pcs? It has been a long time since I set up ccm. So, I have probably done something stupid here. I know the account has to be in the local admin group, but I also have it in the domain admins group. I'm guessing it is the second part that is the stupid bit. Correct?
It is a system account, but I should probably go ahead and pull it out of the domain admin group, right? Any guidance on setting permissions/access for that account? I'm assuming the way I have it is very dangerous.
Thanks