Can device administrator install local software/applications on a device

Kavindu Dayananda 76 Reputation points
2020-11-17T04:14:03.807+00:00

Hi,

We have some PCs deployed via a "Standard User" autopilot profile (Hybrid Azure AD). However we have created a policy to get a elevated prompt when a user wants to install a software and if we enter global administrator credentials, it will install the application. But we don't want to give helpdesk users this GA permissions and want to know whether "Device Administrator" in Azure AD can perform this?

Regards,

Kavindu

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,713 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,244 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,315 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 42,796 Reputation points Microsoft Vendor
    2020-11-17T06:49:36.79+00:00

    @Kavindu Dayananda , For the users with device administrators role, they become local machine administrators on all Windows 10 devices that are joined to Azure Active Directory. From your description, it seems the devices are Hybrid Azure AD device. Based on my research, it is not suitable for Hybrid Azure AD joining devices. We can see more details in the following link:
    https://dirteam.com/sander/2020/08/31/knowledgebase-the-device-administrator-role-is-not-available-on-the-roles-and-administrators-pane-in-the-azure-portal/
    Note: Non-microsoft link, just for the reference.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. Kavindu Dayananda 76 Reputation points
    2020-11-17T07:00:04.33+00:00

    Hi Crystal,

    Thanks for your reply.

    I understand that "Device Administrator" will not work on "hybrid azure ad" joined PCs, but then what is the recommended way of having this? I couldn't find a proper MS article for this.

    Regards,
    Kavindu