Hello @nasha mehr , if the users are being added as admin in other Azure AD joined devices, they might be being set following the Additional local administrators on all Azure AD joined devices feature configuration. Please take a look to Manage the device administrator role for information on how to add or removed such users.
Let us know if this answer was helpful to you or if you need additional assistance. If it was helpful, please remember to accept it so that others in the community with similar questions can more easily find a solution.