I'm getting around to deploying LAPS.
Our system has 3 physical DCs and no other servers.
The DC platforms should be well-capable of supporting virtual machines - but aren't yet.
In everything that I've read recently, it's not recommended to install LAPS fat client on a DC but, rather, on a "management server" whatever that is.
1) I could easily annoint a domain-joined Windows 10 Pro workstation to be a "management server" as I already have some that qualify
2) I might also set up a Windows Standard 2019 virtual machine on one of the DC platforms.
The former will be easiest if that's an acceptable approach - as we won't have to build up and support another machine.
The latter will be more involved (for me) but surely doable.
What are the pros and cons in your view?