Change account type Azure Ad join

Vortal 1 Reputation point
2021-03-08T10:45:37.343+00:00

Good morning to all,

I have this problem that i´m trying to solve it but after some intense reseacrh i can´t find a solution.

When i do Azure AD join with an account it always adds the user as a local administrator. My question is, how can i change this default configuration? and how can i change the account type to standard for a large number of users without doing one by one.

Thank you,

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Pa_D 1,071 Reputation points
    2021-03-08T21:24:21.767+00:00

    You have to use Autopilot.

    • When you setup Autopilot, you have an option to make enrolling user a standard one.
    2 people found this answer helpful.
    0 comments No comments

  2. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2021-03-09T00:39:41.717+00:00

    Hi @Vortal ,

    Windows Autopilot should be the solution you are looking for. Reference: How to manage the local administrators group on Azure AD joined devices

    Autopilot provides you with an option to prevent primary user performing the join from becoming a local administrator.

    The other option is bulk enrollment, since an Azure AD join performed in the context of a bulk enrollment happens in the context of an auto-created user. Users signing in after a device has been joined are not added to the administrators group.

    EDIT: I answered this before seeing that someone else had commented the same thing, since my browser did not refresh to show the comment. But the previous answer is right :)

    0 comments No comments

  3. Vortal 1 Reputation point
    2021-03-09T12:23:23.37+00:00

    Hi there,

    Ok i have to create an auto pilot profile with my specifications, including enrolling the account as a standard one. But the problem is that i have already many devices joined on AzureAD as a local administrator and i want to change them to standard without the need of access the computer itself.

    I checked the bulk enrollment option but it seems not doing what i need. Is there a way to do this, lets say via powershell command?

    Thank you,

    0 comments No comments

  4. Gurumoorthi J 0 Reputation points
    2023-04-06T05:22:55.0366667+00:00

    How to Azure AD Join Administrator type change to standard type in Azure portal policy.....

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.