Forum Discussion
Azure AD user in Windows 10 - local admin problem
- Mar 17, 2018
Hi
Like I said, we do not have AAD Premium, EMS, Intune licenses. Those steps require EMS licenses or AAD Premium.
I was able to set the secondary login account as admin account. Login using this secondary account, go to Control Panel/User Accounts/User Accounts/Change your account type and use O365 admin account or the first account used to login to PC to go past UAC. This way you can upgrade user account as local admin.
Based on this link
https://community.spiceworks.com/topic/1580701-azure-ad-users-given-local-admin-permissions
it is not good idea to downgrade the first (O365)account used to login to PC as standard user.
Prefer to use O365 admin account or some other O365 account used as local admin account when login the first time to PC and add the actual user account to PC after this. This way normal users do not have local admin permissions and you dont have to downgrade user account permissions.
The first user that signs in on Windows 10 automatically becomes a local admin. Alle users after that will be standard users, unless they are an admin in Office 365.
I believe that without Azure AD Premium licenses, you cannot add extra local admins from the management panels in Office 365.
However, when you sign in to a Windows computer as user with Administrator privileges, you can add other users and assign the admin rights on that computer. To do this, go to the settings panel > Accounts > Other People. There you see the other users (or add them) and can change the account type from standard user to administrator.