Removing local admin from multiple users using Endpoint Manager

Marcus Heimstad 1 Reputation point
2022-11-22T13:51:25.273+00:00

Hi,

I'd like to remove Local Admin on a select group of users' devices.
I see that in Account Protection in Endpoint Manager there seems to be functionality for this, but I can't quite get it to work.

I've created a group, where I've added the Users that I'd like this to affect.
In Account Protection, I've created a policy to Remove Users/Group from Admin, and selected this group:
263122-image.png

Then I have assigned this policy to the same group:
263056-image.png

This does not work for me.
If I add the user directly in the "Remove Users/Group" - part, it works just fine. But it does not work if I'm using this group as "who should be removed".
It would make it very tedious to maintain if I have to manually add people to this policy every time we get a new employee that should not have local admin, instead of just having 1 group that serves as an assignment, as well as a "selector" for who should be removed.

Does anyone know what I'm doing wrong here?

Thanks! :)

Microsoft Security Intune Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2022-11-23T05:09:55.13+00:00

    @Marcus Heimstad , Thanks for posting in Q&A.

    Based on my testing, I find if I add group under Remove (update). it will only remove the same group from the local administrators group. The user in the group will still be kept。 The same result as yours.

    Therefore, if currently it is the user we want to remove from local administrators group, we need to add the user under remove(update). Or we can also consider the Add (Replace) action. It replaces the members of the selected groups with the new members you specify for this action.
    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#configure-the-profile

    However, if the existing option didn't meet your requirement, you can try to feedback to Intune uservoice to improve the feature.
    https://feedbackportal.microsoft.com/feedback/forum/ef1d6d38-fd1b-ec11-b6e7-0022481f8472

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.