> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v2.1/readme.md).

# Home

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-6fea344e7b8c8c19103fe60f957f00aab8579e61%2Faccess-manager-logo.png?alt=media)

{% hint style="warning" %}
**Access Manager v3.1 is now available.** This documentation is for Access Manager v2.1, which is supported until 10 November 2026. See [what's new in Access Manager v3](https://docs.lithnet.io/ams/v3.1/whats-new) and the [upgrading from v2 guide](https://docs.lithnet.io/ams/v3.1/installation/upgrading-from-v2).
{% endhint %}

Lithnet Access Manager is a tool that allows you to safely delegate sensitive administrative access to computers in your organization in a modern and user-friendly way.

It provides a web-based interface that allows users to request local admin/root passwords, BitLocker recovery keys, and grant just-in-time administrative access to their own accounts.

It is fully compatible and works out-of-the-box with Microsoft LAPS, but also comes with its own agent, which expands LAPS coverage to Azure AD joined and registered devices, as well as macOS and Linux devices.

Access Manager provides a granular permission model, coupled with a detailed auditing system, both of which are extensible using PowerShell.

Modern authentication is a key feature of Access Manager, with support for OpenID Connect, allowing strong authentication and MFA with cloud-based identity providers such as Azure AD and Okta. On-premises providers have not been forgotten, with full support for WS-Federation (ADFS), smart cards, and if you need it, integrated windows authentication.

#### Defend against ransomware and other lateral movement-based attacks

Access Manager has one simple goal. To reduce the likelihood and impact of a wide-spread compromise in your environment by removing permanent administrative access to your workstations and servers. By making sure every computer has a unique local admin password (through the use of Microsoft LAPS or the Lithnet Access Manager Agent), and removing all other members of the built-in local *Administrators* group, you can limit the ability for credential-stealing ransomware to move laterally across your environment. Access Manager makes it as seamless as possible for admins to access LAPS passwords, or grant themselves temporary just-in-time admin access. Access Manager isn’t a silver bullet guaranteed to protect you from this type of attack, but it forms a fundamental part of a defense-in-depth strategy against them.

We recommend you have a look at our other product [Lithnet Password Protection for Active Directory](https://docs.lithnet.io/password-protection/v1.0/), for a tool to help strengthen your environment against commodity password-based attacks.

#### Features

**Web-based access to local admin passwords**

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-515ca2a161eae231658160372972d0e626757bbc%2Fweb-request-laps.gif?alt=media)

Access Manager provides a simple web-based and mobile-friendly interface for accessing local admin passwords for Windows, macOS and Linux devices. There’s no need for admins to install custom software, or have access to AD administrative tools to access LAPS passwords.

Administrators also have the option of forcing an expiry time when a password is accessed. This ensures that the password is rotated after use.

We use LAPS passwords ourselves, so we know they can be painful at times. We try to take away as much of that pain as possible. From using fonts where you can actually see the difference between a lower-case L and a capital I, to showing a breakdown of the password using the NATO phonetic alphabet to make it easy to read it out to someone. Have you ever found yourself needing to type a LAPS password into a Windows logon screen? Have Access Manager read the password to you while you type with its text-to-speech capability!

Whether you use Microsoft LAPS, or the Lithnet Access Manager agent, the user experience is the same.

**Access historical local admin passwords**

Deploying the Lithnet Access Manager Agent to your fleet allows you to upgrade to encrypted local admin passwords and gain the benefit of having previous local admin passwords stored in the directory as well. This means no more issues getting locked out of computers when they are restored from backup or reverted from a snapshot.

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-e5be1436f30cc1160f4eba2a30af0b6e1b045088%2Fweb-request-laps-history.gif?alt=media)

**Just-in-time administrative access to computers**

Using the same web interface, users can request that their account be added to a group that is a member of the local administrators group of the computer. This access is temporary and automatically removed after the allowed time period.

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-ce9db2fe536d216aa05db4d9ceb48ca1c5de6527%2Fweb-request-jit.gif?alt=media)

**Just-in-time access to custom roles**

Access Manager allows you to provide your users with just-in-time access to custom roles that you define. When a user is granted access to a role, Access Manager will add them to the corresponding Active Directory group, and automatically remove them when the allowed time period has elapsed.

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-a2d967df3a3951924c1a834045ace1100761ca9e%2Fweb-request-jit-roles.gif?alt=media)

**Easy access to BitLocker recovery passwords**

Authorized users can also request access to the BitLocker recovery passwords for a computer through the same easy-to-use web interface.

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-61d31fca217cae02099df341ed1330d0163c42f6%2Fweb-request-bitlocker.gif?alt=media)

**Audit success and failure event logs**

All success and failure events are logged to the Windows event log and a file. Optionally, you can send audit events via email, webhooks, and even PowerShell.

The webhook functionality makes it really easy to get alerts via Slack or Microsoft Teams, and there are even built-in templates for these systems.

![](https://1174763835-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYKUIJoHjACu79Ekwwf7i%2Fuploads%2Fgit-blob-76017eac21e38052841ed1fe62f4f12788194caa%2Fauditing-example-slack.png?alt=media)

**Modern authentication options**

The web app supports traditional integrated windows authentication, as well as external authentication providers such as [ADFS](/ams/v2.1/configuration/setting-up-authentication/setting-up-authentication-with-adfs.md) or 3rd party OpenID Connect providers such as [Azure AD](/ams/v2.1/configuration/setting-up-authentication/setting-up-authentication-with-azure-ad.md) and [Okta](/ams/v2.1/configuration/setting-up-authentication/setting-up-authentication-with-okta.md). Using an external authentication provider allows you the option of providing additional protections for the application such as multifactor authentication.

#### Download the app

[Download the app](/ams/v2.1/installation/downloads.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v2.1/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
