How can I change the permissions of the primary user so that it can install software?

Vanmassenhove Ben (VNZ) 20 Reputation points
2023-05-15T13:08:31.6533333+00:00

We have an AAD joined device that was enrolled by a user who left the organization. The device was transfered to a newly hired colleague. Login in to the device with the new user's username and password was easy. No problems there. We were also able to change the device's primary user to the new colleague. The user however can't install software. A popup screen appears saying he or she doesn't have permission. What's the issue here? I read here and there that only the user who enrolled the device is local admin, but it must be possible to change that somewhere, no?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,421 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,691 questions
0 comments No comments
{count} votes

Accepted answer
  1. Pavel yannara Mirochnitchenko 11,801 Reputation points MVP
    2023-05-15T14:16:58.32+00:00

    You have Local Admin role in AzureAD, you can assign some users there and they will benefit with local admin rights. It is recommend to have dedicated workstation admins for that job, and not allowing everyone or simple users to having that role.

    User's image

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Lu Dai-MSFT 28,356 Reputation points
    2023-05-16T02:07:06.78+00:00

    @Vanmassenhove Ben (VNZ) Thanks for posting in our Q&A.

    Based on my understanding, not all softwares needs to have admin permission to be installed. This popup screen "doesn't have permission" appears when this software needs to have admin permission.

    Given this situation, it is suggested to try to add this new Azure AD user to the local admin group. And then check if this user can install the software successfully.

    https://www.anoopcnair.com/manage-local-admins-using-intune-group-mgmt/

    Note: Non-Microsoft link, just for the reference.

    If there is anything update, feel free to let us know.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.