Disconnect from organization with password?

Patrick Meier 21 Reputation points
2020-08-27T09:00:06.907+00:00

Hi everyone,

A local admin is able to unjoin a computer from a local domain in the Windows Settings > Accounts > Access work or school > click on the 'Disconnect' button. The local admin can do this without a password!

But if the local admin unjoins the computer from the local domain in Control Panel\All Control Panel Items\System > Change settings > click on 'Change' next to 'To rename this computer...' > set 'Member of' to 'Workgroup', a password from a domain admin is needed.

I searched for hours for a GPO that enforces a password for 'Disconnect from organization' or disables this button completely. I did not find anything.

Is there really no GPO for that?

We don't want local admins to unjoin their computers from our domain.

Best regards,
Patrick

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,959 questions
Windows 10 Setup
Windows 10 Setup
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
1,918 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Fan Fan 15,306 Reputation points Microsoft Vendor
    2020-08-28T00:48:34.27+00:00

    Hi,

    Based on my research , there is no option to disables this button completely.
    But we can enforces a password for 'Disconnect from organization "through GPO settings .
    We can configure the UAC settings under computer configuration>windows settings>>Security Settings >Local Policies>Security Options as following, then when you try to Disconnect from organization, a credential is needed.

    21062-8281.jpg
    But this policy is not just for this option,
    • Prompt for credentials: When an operation requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

    0 comments No comments

  2. Patrick Meier 21 Reputation points
    2020-08-28T08:16:03.78+00:00

    Hi @Fan Fan ,

    Thank you for your answer. Indeed, it seems to work.

    So the admin must enter his password for all admin operations/functions, although he is logged in as Admin. This is not so great. We will discuss this in the team, but I think we will probably do without it for convenience.


  3. Babak Ramak 1 Reputation point
    2020-08-31T06:40:35.813+00:00

    Dears,

    This section (Access work or school) is related to Microsoft Account. You can disable it by followings:

    GPO: Windows Settings -> Security Settings -> Local Policies -> Security Options -> Accounts: Block Microsoft accounts

    Registry: HKLM\SOFTWARE\Microsoft\PolicyManager\default\Settings\AllowYourAccount\value=0

    Reference: https://social.technet.microsoft.com/Forums/en-US/68047b9a-863a-48cf-9ccb-beb51cd023cb/remove-quotaccess-work-or-schoolquot-accountsconnections-as-admin?forum=win10itprogeneral