Azure AD Join Devices

Abdulhamid Elfsatwi 21 Reputation points
2022-11-05T15:18:29.317+00:00

We have a branch located far from our main office. we need to join the devices to Azure Active directory. When the user takes the steps to join the device to Azure AD, he will become a member of the local administrator group.
According to company policy, the user cannot be a member of that group; only the helpdesk team is permitted to be a member of the local admin group.
What is the best solution to this problem?

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Enrollment
0 comments No comments
{count} votes

Accepted answer
  1. Manu Philip 20,206 Reputation points MVP Volunteer Moderator
    2022-11-05T19:45:07.537+00:00

    By default, Azure AD adds the user performing the Azure AD join to the administrator group on the device. If you want to prevent regular users from becoming local administrators, you have the following options:

    Windows Autopilot - Windows Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator by creating an Autopilot profile.
    Bulk enrollment - An Azure AD join that is performed in the context of a bulk enrollment happens in the context of an auto-created user. Users signing in after a device has been joined aren't added to the administrators group.

    ----------

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,406 Reputation points Microsoft Employee Moderator
    2022-11-07T17:44:52.943+00:00
    1 person found this answer helpful.

  2. Jason Sandys 31,406 Reputation points Microsoft Employee Moderator
    2022-11-08T15:33:00.867+00:00

    Do you think this feature will let me replace them with a help desk team?

    I don't see why not.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.