How to remove 'Local Admin rights' from Azure AD joined devices?

Anonymous
2022-04-27T09:42:06.053+00:00

When setting up a Windows device, the user who does so becomes local Admin. These same users are now enrolled within Intune however they still hold 'local admin' rights and therefore have sufficient credentials to download software etc without admin credentials required. How do we revoke this 'local admin' access on these users/devices to stop them from doing this? If it's a Powershell script that is needed, dows anyone have a working one? Many thanks

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,302 questions
{count} votes

Accepted answer
  1. Jason Sandys 31,311 Reputation points Microsoft Employee
    2022-04-27T14:38:43.463+00:00
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Harley Butcher 11 Reputation points
    2022-04-27T09:45:36.287+00:00

    You can remove the local admin rights by going into computer management > users and groups > administrators

    However this will not stop it from happening in future on new devices.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.