Share via

Managed Device without admin privileges

Marcelo Saplagio 40 Reputation points
2025-09-12T21:55:36.4466667+00:00

Hi. Can I ask for help? I recently purchased a Business Standard and Migrating my whole business from Google to Microsoft.

Here is the scenario:

I did a reset on my device and set it as work and managed. Initially okay as I was able to sync the data then later found out that i cannot install office. It promoted an admin email and password. When I added the email - it says requested operation requires elevation. I have set all 110 access to that email in roles in the entra users but still the same. Now, I think I am completely locked on the device. I cannot install apps, cannot access cmd, can be rebooted to safe mode, but there are no more admin access, and cannot add admin as well.

Anyone had the same scenario? please help.

Windows for business | Windows 365 Business
0 comments No comments

Answer accepted by question author

  1. Harry Phan 19,565 Reputation points Independent Advisor
    2025-09-13T02:32:54.6966667+00:00

    Hello Marcelo,

    From your description, it sounds like the device has been enrolled into Microsoft Intune or Azure AD Join, but the assigned user account lacks local administrator privileges. Even though you've granted full access roles in Microsoft Entra ID, those roles apply to cloud resources and don’t automatically elevate local permissions on the device.

    To resolve this, I recommend checking the Intune Device Configuration Profile or Endpoint Manager settings. Specifically, ensure that the user is added to the Local Administrators group via a device configuration policy. You can do this by navigating to Endpoint Security > Account Protection > Local user group membership and assigning the correct group membership.

    If you're completely locked out and unable to access CMD or install apps, you may need to perform a fresh reset using a recovery USB and reconfigure the device with proper admin provisioning during setup. Be sure to use an account that’s pre-assigned as a local admin via Autopilot or manual provisioning.

    Once access is restored, you can re-enroll the device and apply the necessary policies to avoid future lockouts.

    =====

    I hope this helps you get back on track quickly. If this guidance proves useful, feel free to hit “Accept Answer”—it’s always great to know when the solution lands well 😊

    T&B, Harry.

    Was this answer helpful?

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.