Check out this new capability we added in January (of this year): https://techcommunity.microsoft.com/t5/intune-customer-success/new-settings-available-to-configure-local-user-group-membership/ba-p/3093207
How to remove 'Local Admin rights' from Azure AD joined devices?
When setting up a Windows device, the user who does so becomes local Admin. These same users are now enrolled within Intune however they still hold 'local admin' rights and therefore have sufficient credentials to download software etc without admin credentials required. How do we revoke this 'local admin' access on these users/devices to stop them from doing this? If it's a Powershell script that is needed, dows anyone have a working one? Many thanks
-
Jason Sandys 31,311 Reputation points Microsoft Employee
2022-04-27T14:38:43.463+00:00
1 additional answer
Sort by: Most helpful
-
Harley Butcher 11 Reputation points
2022-04-27T09:45:36.287+00:00 You can remove the local admin rights by going into computer management > users and groups > administrators
However this will not stop it from happening in future on new devices.