AAD JIT and Workstation Local administrator access

Tim Earp 1 Reputation point
2021-10-15T11:25:50.393+00:00

Sorry if this is the wrong forum.. happy to move to the correct if required.

Hi! I'm looking to remove all users from having Local Administrator (hang over from an Azure join) on their workstations. Some users do still require/demand this and I have to be able to cater for this so that the business buy into the change.

My thoughts are to purchase AAD P2 licenses and just Just In Time to grant access to an Azure group that will be within the workstation 'administrators' group. Is this something that anyone has had experience of/has read a blog/question has already been asked and answered please?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,565 questions
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,231 Reputation points Microsoft Employee
    2021-10-19T10:31:26.757+00:00

    @Tim Earp Thanks for reaching out.

    I have read a detailed blog about this and that should help you in your current decision as well. Please check :
    https://joymalya.com/manage-local-admin-accounts-with-intune/

    Disclaimer: This response contains a reference to a third-party World Wide Web site. Microsoft is providing this information as a convenience to you. Microsoft does not control these sites and has not tested any software or information found on these sites; therefore, Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. There are inherent dangers in the use of any software found on the Internet, and Microsoft cautions you to make sure that you completely understand the risk before retrieving any software from the Internet.

    0 comments No comments