Using Intune to enforce local administrator of workstations like Group Policy Preferences.

EnterpriseArchitect 5,136 Reputation points
2024-01-17T04:30:14.3966667+00:00

How can I achieve the same thing with the Intune policy to enforce the local administrator of the workstation ?

  • Remove any local administrator users, other than 'ITSupport'

Group Policy Preferences: https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/using-group-policy-preferences-to-manage-the-local-administrator/ba-p/259223

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
375 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,807 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
147 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,730 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 46,171 Reputation points Microsoft Vendor
    2024-01-17T05:17:16.2766667+00:00

    @EnterpriseArchitect, Thanks for posting in Q&A. To remove users from local administrators, we can configure it via Local user group membership (preview) profile. Add (Replace): Replace the members of the selected groups with the new members you specify for this action. Here is a link with more details:

    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#manage-local-groups-on-windows-devices

    But as remove the built-in Administrator account from the built-in Administrators group is blocked at SAM/OS level for security reasons. So we can only remove other users exclude built in administrator from local administrators.

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups?WT.mc_id=Portal-fx#what-happens-if-i-accidentally-remove-the-built-in-administrator-sid-from-the-administrators-group

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful