Event banner
AMA: Windows management with Intune
Event details
remediation powershell script possibly where you poll bultin\adminstrators maybe with net localgroup or the ps equivalent. Probably start with some kind of report as to what was found on what system (dump a csv to a share or to an azure storage? Just spitballing here. Maybe this helps? (https://www.anoopcnair.com/create-a-local-admin-account-intune/)
Panel did a great job covering a much simpler way. Hard part, or at least what I don't know is identifying all the existing local users that are on a device. Say you acquire a company and now you enroll all of those users and devices, you have no idea what is already there for local users and/or what to remove but you do want to add your standard users and admins so while useful, a way to report on what you find so you can then go in and create policies to remove those might be helpful.