How can I remove the user who performed the Microsoft Entra join from the device local administrators group via intune on all devices in my organisation?

William McDonald 0 Reputation points
2024-07-30T17:44:23.9733333+00:00

Originally, my organisation used user accounts to join devices to Entra, which gave all users admin rights on their machines. We are now looking to revoke these privileges. I have seen lots of information about removing the Device Administrator or Global Administrator groups but nothing for the user that joined the device. How can I remove these without having to manually reach each device? Is there an Intune solution?

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,919 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,140 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Neuvi Jiang 1,460 Reputation points Microsoft Vendor
    2024-08-01T08:15:10.4166667+00:00

    Hi William McDonald ,

    Thank you for posting in the Q&A Forums.

    When revoking administrator privileges for users who are joining devices using Entra, if you wish to do so without manually accessing each device, you can indeed utilize the capabilities of Intune and Azure Active Directory (Azure AD) to achieve this goal. Here are some steps and recommendations to help you with this process:

    1. Evaluate the current configuration

    First, you need to understand the current device configuration and user permission settings. This includes which user accounts have been given administrator privileges and how these privileges are assigned through Entra and Intune.

    1. Use Intune Policies to Manage Permissions

    Intune provides a rich set of policy settings that can be used to control device permissions and behavior. You can restrict or revoke a user's administrator privileges by creating or modifying a device configuration policy.

    Create or Edit a Device Configuration Policy: In Intune, you can create a new device configuration policy or edit an existing policy to include restrictions on administrator privileges. This typically involves configuring local user and group settings to disable or remove administrator privileges for specific user accounts.

    Deploy Policy: Deploys the created or modified device configuration policy to the target device group. This way, all devices belonging to the group will receive and apply the new permission settings.

    1. Leveraging Azure AD Group Policy

    If your organization uses Azure AD to manage users and devices, you can also leverage Azure AD's Group Policy feature to further control permissions.

    Create or modify security groups: In Azure AD, you can create new security groups or modify existing groups to include user accounts that need to have administrator privileges revoked.

    Assign roles and permissions: With Azure AD's role and permission management features, you can restrict the permissions of members of these security groups on the device. For example, you can remove these users from the global administrator role and assign them more limited roles

    Best regards

    NeuviJ

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.