Can device administrator install local software/applications on a device

%3CLINGO-SUB%20id%3D%22lingo-sub-1893264%22%20slang%3D%22en-US%22%3ECan%20device%20administrator%20install%20local%20software%2Fapplications%20on%20a%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1893264%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20some%20PCs%20deployed%20via%20a%20%22Standard%20User%22%20autopilot%20profile%20(Hybrid%20Azure%20AD).%20However%20we%20have%20created%20a%20policy%20to%20get%20a%20elevated%20prompt%20when%20a%20user%20wants%20to%20install%20a%20software%20and%20if%20we%20enter%20global%20administrator%20credentials%2C%20it%20will%20install%20the%20application.%20But%20we%20don't%20want%20to%20give%20helpdesk%20users%20this%20GA%20permissions%20and%20want%20to%20know%20whether%20%22Device%20Administrator%22%20in%20Azure%20AD%20can%20perform%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EKavindu%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1893264%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1893625%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20device%20administrator%20install%20local%20software%2Fapplications%20on%20a%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1893625%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F109550%22%20target%3D%22_blank%22%3E%40Kavindu%20Asanga%20Dayananda%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ethere%20are%20a%20few%20options%2C%20a%20good%20summary%20of%20the%20native%20MS%20functionality%20is%20found%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fassign-local-admin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fassign-local-admin%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EYou%20don't%20need%20to%20use%20the%20Global%20Admins%2C%20you%20can%20assign%20Device%20Admins%2C%20but%20they%20can't%20be%20scoped%20they%20are%20admins%20on%20all%20your%20devices.%20With%202004%20we%20got%20an%20option%20via%20a%20config%20profile%20(OMA-URI)%20to%20control%20membership%20in%20local%20Administrators%20group%20on%20Windows%2010.%20That's%20all%20build%20in.%20If%20that%20is%20not%20sufficient%2C%20you%20need%20to%20use%20a%20LAPS%20solution%20out%20there.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHere%20is%20a%20good%20blog%20about%20various%20LAPS%20community%20solutions%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.vansurksum.com%2F2020%2F02%2F11%2Fchallenges-while-managing-administrative-privileges-on-your-azure-ad-joined-windows-10-devices%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EChallenges%20while%20managing%20administrative%20privileges%20on%20your%20Azure%20AD%20joined%20Windows%2010%20devices%20%7C%20Modern%20Workplace%20Blog%20(vansurksum.com)%3C%2FA%3E%3C%2FP%3E%0A%3CP%3Eand%20finally%20there%20are%20official%20products%20providing%20LAPS%20functionality%2C%20to%20mention%20a%20few%2C%20%3CA%20href%3D%22https%3A%2F%2Frealmjoin.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ERealmJoin%20%7C%20Companion%20to%20Intune%3C%2FA%3E%26nbsp%3B(it%20has%20also%20a%20LPAS%20component)%20or%20%3CA%20href%3D%22https%3A%2F%2Fwww.adminbyrequest.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EAdmin%20By%20Request.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1902741%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20device%20administrator%20install%20local%20software%2Fapplications%20on%20a%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1902741%22%20slang%3D%22en-US%22%3EYou%20are%20correct!%20Check%20out%20this%20article%20for%20more%20info%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fassign-local-admin%23manage-the-device-administrator-role%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fassign-local-admin%23manage-the-device-administrator-role%3C%2FA%3E%3C%2FLINGO-BODY%3E
Occasional Contributor
 
 

Hi,

 

We have some PCs deployed via a "Standard User" autopilot profile (Hybrid Azure AD). However we have created a policy to get a elevated prompt when a user wants to install a software and if we enter global administrator credentials, it will install the application. But we don't want to give helpdesk users this GA permissions and want to know whether "Device Administrator" in Azure AD can perform this?

 

Regards,

Kavindu

1 Reply

Hey @Kavindu Asanga Dayananda,

 

there are a few options, a good summary of the native MS functionality is found here: https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin

You don't need to use the Global Admins, you can assign Device Admins, but they can't be scoped they are admins on all your devices. With 2004 we got an option via a config profile (OMA-URI) to control membership in local Administrators group on Windows 10. That's all build in. If that is not sufficient, you need to use a LAPS solution out there. 

Here is a good blog about various LAPS community solutions: Challenges while managing administrative privileges on your Azure AD joined Windows 10 devices | Mod...

and finally there are official products providing LAPS functionality, to mention a few, RealmJoin | Companion to Intune (it has also a LPAS component) or Admin By Request.

 

best,

Oliver