1 vote
we are using RDM Enterprise in a Multi-Domain Environment, each domain with its own LAPS.
atm f.e. the RemoteDesktop Maanager is started on a Client in Domain A. LAPS from Domain A is working, LAPS from Domain B-E isnt, because the Client cannot Access them, cause its not joined .
it would be very helpful when the LAPS-Usage would be handled from the different Devolutions-Gateways which are in the different domains and not by the Client where the Remote-DesktopMAnager is startet.
Hello Marcus,
Good news, we have already added the ability to decrypt LAPS passwords across domains (different than the one that RDM is joined) in our 2025.2 release (coming in June). We still do not support doing it over a Gateway, but this is something we could definitely add as well, I will create a ticket for that feature.
Thanks,
Paul Dumais
Hello Marcus,
Good news, we have already added the ability to decrypt LAPS passwords across domains (different than the one that RDM is joined) in our 2025.2 release (coming in June). We still do not support doing it over a Gateway, but this is something we could definitely add as well, I will create a ticket for that feature.
Thanks,
Paul Dumais
Hello Paul,
thanks for that information, so it is still the client who is doing the LAPS query and needs access to the domains?
Hello Marcus,
Good news, we have already added the ability to decrypt LAPS passwords across domains (different than the one that RDM is joined) in our 2025.2 release (coming in June). We still do not support doing it over a Gateway, but this is something we could definitely add as well, I will create a ticket for that feature.
Thanks,
Paul Dumais
Hello Paul,
thanks for that information, so it is still the client who is doing the LAPS query and needs access to the domains?
Hello Marcus,
Sorry for the delay getting back to you. Yes the client does the LAPS query, but it can work across domains, because we connect to the domain controller directly and fetch the DPAPI decryption keys over RPC, then get the LAPS password over LDAP from the remote domain.
Paul