Autopilot Deployment profile OOBE User Account type Administrator is not created under Administrator group

Aslan 0 Reputation points
2024-07-08T07:24:29.65+00:00

In Deployment profile OOBE I have set user account type Administrator. But post Autopilot provision completion sucessful I don't see user is added to Administrator group. How to troubleshoot why user is not added to Administrator group. Please explain me which MDM Diagnostic logs I need refer. I looked all the logs but I didn't get any trace. I checked couple of event viewer entry I got some info but it does not helped me. please suggest. Attached reference screenshot.

Windows Autopilot
Windows Autopilot
A collection of Microsoft technologies used to set up and pre-configure new devices and to reset, repurpose, and recover devices.
471 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,377 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-07-08T07:40:30.8866667+00:00

    Keeping your issue aside, may I suggest that giving your end users admin rights is a very idea and you are potentially opening the attack surface area? Instead, you should look at implementing cloud LAPS.


  2. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-07-08T19:24:43.8+00:00

    What is the value of “Registering user is added as local administrator on the device during Microsoft Entra join” under Entra>Devices?


  3. Crystal-MSFT 49,436 Reputation points Microsoft Vendor
    2024-07-09T01:53:43.6166667+00:00

    @Imran Katike, Thanks for posting in Q&A. Based on my researching, there's a compatibility problem between the Windows Autopilot device preparation policy User account type setting and the Microsoft Entra ID Local administrator settings. I notice we want the user to be a local administrator user on the device. If so, please set the Microsoft Entra ID Local administrator settings is set to All.

    https://learn.microsoft.com/en-us/autopilot/device-preparation/known-issues#conflict-between-microsoft-entra-id-and-windows-autopilot-device-preparation-local-administrator-setting

    Meanwhile, if it occurs in Windows Autopilot user-driven hybrid Microsoft Entra deployments and there's another user on the device that already has Administrator rights, it will also cause the issue. Please don't create another account until after the Windows Autopilot process is complete.

    https://learn.microsoft.com/en-us/autopilot/known-issues#windows-autopilot-user-driven-hybrid-microsoft-entra-deployments-dont-grant-users-administrator-rights-even-when-specified-in-the-windows-autopilot-profile

    Please try the above suggestion and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.