How to remove local admin right on all users devices via intune

J-3804 1,601 Reputation points
2024-01-30T04:28:57.2066667+00:00

Hi team,How can I remove local admin rights on all users' devices via Intune? Appreciate your help.

Microsoft Security | Intune | Configuration
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2024-01-30T05:31:30.9666667+00:00

    @J-3804, Thanks for posting in Q&A. In Intune, there's feature under Endpoint security > Account protection>Local user group membership to manage local user group membership. We can choose Remove (Update) if we want to remove specific user from local administrators group. Here is a link with more details for your reference.

    https://techcommunity.microsoft.com/t5/intune-customer-success/new-settings-available-to-configure-local-user-group-membership/ba-p/3093207

    As a note, removing the built-in Administrator account from the built-in Administrators group is blocked at SAM/OS level for security reasons. Attempting to do so will result in failure.

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups#what-happens-if-i-accidentally-remove-the-built-in-administrator-sid-from-the-administrators-group

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.