How can I change the permissions of the primary user so that it can install software?

Vanmassenhove Ben (VNZ) 20 Reputation points
2023-05-15T13:08:31.6533333+00:00

We have an AAD joined device that was enrolled by a user who left the organization. The device was transfered to a newly hired colleague. Login in to the device with the new user's username and password was easy. No problems there. We were also able to change the device's primary user to the new colleague. The user however can't install software. A popup screen appears saying he or she doesn't have permission. What's the issue here? I read here and there that only the user who enrolled the device is local admin, but it must be possible to change that somewhere, no?

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
14,865 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
2,741 questions
0 comments No comments
{count} votes

Accepted answer
  1. Pavel Yannara Mirochnitchenko 8,721 Reputation points
    2023-05-15T14:16:58.32+00:00

    You have Local Admin role in AzureAD, you can assign some users there and they will benefit with local admin rights. It is recommend to have dedicated workstation admins for that job, and not allowing everyone or simple users to having that role.

    User's image

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Lu Dai-MSFT 24,446 Reputation points Microsoft Vendor
    2023-05-16T02:07:06.78+00:00

    @Vanmassenhove Ben (VNZ) Thanks for posting in our Q&A.

    Based on my understanding, not all softwares needs to have admin permission to be installed. This popup screen "doesn't have permission" appears when this software needs to have admin permission.

    Given this situation, it is suggested to try to add this new Azure AD user to the local admin group. And then check if this user can install the software successfully.

    https://www.anoopcnair.com/manage-local-admins-using-intune-group-mgmt/

    Note: Non-Microsoft link, just for the reference.

    If there is anything update, feel free to let us know.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.