LAPS (Local Administrator Password Solution) provides centralized storage of local users passwords in AD with periodic randomizing.
"…it mitigates the risk of lateral escalation that results when customers have the same administrative local account and password combination on many computers."
Storage in clear text, transmission is encrypted (Kerberos).
Configurable using GPO.
Access control for reading clear text passwords using ACLs. Only Domain
Admins and explicitly allowed users can read the passwords.
Enumeration

Get-DomainOU | Get-DomainObjectAcl -ResolveGUIDs | Where-Object {($_.ObjectAceType -like 'ms-Mcs-AdmPwd') -and ($_.ActiveDirectoryRights -match 'ReadProperty')} | ForEach-Object {$_ | Add-Member NoteProperty 'IdentityName' $(Convert-SidToName $_.SecurityIdentifier);$_}

Import-Module .\ADModule-master\Microsoft.ActiveDirectory.Management.dll
Import-Module .\ADModule-master\ActiveDirectory\ActiveDirectory.psd1
Import-Module .\AdmPwd.PS\AdmPwd.PS.psd1
Import-Module .\Get-LAPSPermissions.ps1

Get-DomainObject -Identity <targetmachine$> | select -ExpandProperty ms-mcs-admpwd
