Share via

No Admin Access After SCCM Client Install

bob ross 101 Reputation points
2021-06-30T20:20:08.577+00:00

I finally got my SCCM Client install from Intune to an AAD Joined device working. Strangely enough my online admin account cannot elevate on the device any longer. This device has all workloads set to intune. My admin account is an intune admin, cloud device admin, and local aad device admin. Has anyone else seen or gone through this?

to clarify - the device went from aad joined to hybrid aad joined. it is not on the domain. it is showing in sccm and i went ahead and added it to the pilot intune group that i have set up for the configuration workloads

Microsoft Security | Intune | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,421 Reputation points Microsoft Employee Moderator
    2021-07-06T15:07:59.32+00:00

    I am unable to try with my domain Admin account as it only asks for an email addresss

    Right because that identity and its authority (your on-prem AD domain) are unknown to the device.

    Any idea why the admin access no longer works?

    What does this mean in technical terms? What are you trying to do exactly? WHat exactly is not working? What messages are displayed when you are attempting the action? Etc.?

    Was this answer helpful?


  2. Jason Sandys 31,421 Reputation points Microsoft Employee Moderator
    2021-06-30T22:07:06.03+00:00

    the device went from aad joined to hybrid aad joined

    This is not possible without manually unjoining the device from the AAD domain first. Co-management (by virtue of enrolling the device into Intune) is not the same as hybrid AAD domain join and is unrelated to the device's domain join state. Also, hybrid AAD join, by definition, is an on-prem domain join + AAD registration by the device.

    However, if you did somehow change the domain join state of the device, then that explains why your AAD account no longer works as an HAADJ device has no concept or ability to authenticate an AAD account for local purposes (like local admin permissions).

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.