How to remove AAD users as local admins

Bhaskar Sharma 20 Reputation points
2023-08-03T19:31:33.5633333+00:00

Hi,
All our devices have AAD accounts added as local admins. How can I remove all these users as admins via intune
I have the following setup in endpoint security >
User groups > remove > added all AAD users

assignment
assigned to all devices.

This shows as succeeded in report but users are still added as local admins
Thank you

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,274 questions
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,486 Reputation points
    2023-08-04T02:32:18.34+00:00

    @Bhaskar Sharma Thanks for posting in our Q&A.

    For this issue, I have done the test in my lab. It works well. I will share you some information.

    In my test, I want to remove "AzureAD\test2" in the administrator group and I deploy this profile to my device group. Here is my configuration:

    User's image

    User's image

    After this profile shows successful deployment, I restart the target device and the I find that "AzureAD\test2" is removed successfully.

    User's image


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


2 additional answers

Sort by: Most helpful
  1. kam 0 Reputation points
    2023-08-03T21:43:37.7033333+00:00

    I had the same issue. If you have your users do a reboot are they still local admins?

    0 comments No comments

  2. Rudy Ooms 691 Reputation points MVP
    2023-08-04T05:29:40.9666667+00:00

    Multiple options.... I have written a couple of blogs about this topic

    https://call4cloud.nl/2021/04/dude-wheres-my-admin/

    IN that blog I am also mentioning the possiblity to remove local admins with a powershell script

    https://call4cloud.nl/2020/03/remove-all-local-admins/


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.