Microsoft has quietly made its Local Administrator Password Solution (LAPS) a mandatory configuration for Windows 11 Enterprise devices joined to Azure AD or on-premises Active Directory. In this episode, Lucas and Luna break down what the mandate means for IT administrators: why Microsoft is enforcing randomized, rotated local admin passwords, how LAPS works under the hood, and what happens if your organization hasn't deployed it yet. They walk through the specific Group Policy and Intune settings that trigger compliance enforcement, the February 2026 Windows servicing stack update that enabled the mandate, and the security rationale behind eliminating static local admin passwords. Lucas shares data from Microsoft's 2025 Digital Defense Report showing that lateral movement using compromised local admin credentials was involved in 67 percent of ransomware incidents. Luna asks about legacy systems and offline devices, and Lucas explains the fallback options and exceptions. By the end, you'll understand exactly what your IT team needs to configure before the next compliance scan hits.