Managing and enforcing security policies for devices and apps to protect organizational data through Intune
It sounds like you're experiencing issues with the application of the Account Protection policy in Intune, particularly with the local administrator group management. Here are some steps and considerations that might help you troubleshoot the situation:
- Policy Caching: Intune policies can sometimes take time to propagate or may have caching mechanisms that retain previous settings. Ensure that the policy has been fully removed from the device by checking the Intune management console for the policy status.
- Device Sync: Even though you mentioned syncing without errors, consider forcing a manual sync from the device to Intune to ensure that all policies are up to date. You can do this through the Company Portal app or by using the command line.
- Policy Conflicts: Check if there are any other conflicting policies that might be reapplying the local administrator settings. If multiple policies target the same group or user, the most restrictive policy may take precedence.
- Review Logs: Investigate the logs on the device for any indications of policy application or errors. You can use the Event Viewer to look for logs related to Intune or policy application.
- User Group Membership: Ensure that the user is not part of any other group that might have conflicting permissions or policies applied. Sometimes, group memberships can override individual settings.
- Reassigning Policies: After removing the policy, wait a sufficient amount of time before reassigning it to a different group. This can help avoid any residual effects from the previous policy application.
- Contact Support: If the issue persists, consider reaching out to Microsoft Support for assistance. They may have additional tools or insights into the backend processes that could help resolve the issue.
By following these steps, you should be able to identify the cause of the issue and prevent it from occurring with other devices in the future.
References: