How to remove 'Local Admin rights' from Azure AD joined devices?

support-117 21 Reputation points

When setting up a Windows device, the user who does so becomes local Admin. These same users are now enrolled within Intune however they still hold 'local admin' rights and therefore have sufficient credentials to download software etc without admin credentials required. How do we revoke this 'local admin' access on these users/devices to stop them from doing this? If it's a Powershell script that is needed, dows anyone have a working one? Many thanks

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
2,721 questions
{count} votes

1 additional answer

Sort by: Most helpful
  1. Harley Butcher 11 Reputation points

    You can remove the local admin rights by going into computer management > users and groups > administrators

    However this will not stop it from happening in future on new devices.