The 2 SIDs Azure GA and Azure Device local admin already get added on azure ad joined devices. What you are doing will add additional local admins which should be enough. However consider the ramifications of adding additional local admins. Maybe consider using PIM to add session controls.
How to assign Admin access and remove any user from local admin group to Intune join devices
Hi
We want to achieve admin access for our SDM team from Intune joined devices. Currently we are enrolling device using automatic enrollment without Autopilot. Which user become administrator of that device, to tackle this. We are using Account protection in Intune to replace the user or group with the group assigned to SDM team. It is doing its job well and replacing the group with the defined one.
is this enough to assign the admin access to SDM team or we need to assigned the role Azure AD joined Device local administrator to that groups too?
Just to inform, the admin account was created in on premises and sync with Azure AD. As we have hybrid environment too.
Microsoft Security Microsoft Entra Microsoft Entra ID
Microsoft Security Intune Other
2 answers
Sort by: Most helpful
-
Rahul Jindal [MVP] 10,911 Reputation points MVP
2023-02-22T19:03:38.7166667+00:00 -
Crystal-MSFT 53,981 Reputation points Microsoft External Staff
2023-02-27T05:08:30.4066667+00:00 @Ritesh Sharma. Thanks for posting in Q&A.
For Azure AD Joined Device Local Administrator role, any user with the role permissions will have Local Admin access on the Azure AD Joined devices in the environment. In General, When the privileged user logs in to the Azure AD joined computer, few Security Principals are getting added to the computer. They are the Azure AD Global Administrator and Device Local Administrator role and the user performing the Azure AD join. If you want to the SDM team to be local admin on all Azure AD joined device, you can assign this role.
For other scenario, we can use Account protection policy to update the local administrators group.
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy
For license, if the user needs to deploy Intune policy. Please assign Intune license to the user.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.