Sep 21 2023 01:17 AM
Hello,
We are in the process of setting up Intune for our organisation and are working on designing the process for enrolling each user's device. Currently, each users' account is set up as a local admin account, and ideally we would find some way to link this to their AD account in intune.
Does anyone know how to accomplish this? Simply enrolling the device via company portal doesn't connect the account it was enrolled from.
Thanks in advanced
Sep 21 2023 05:51 AM
Hi @Louis_H440,
To link a local admin account to an AD account in Intune, you can use the following steps:
Once the device is enrolled and the user account is linked to the AD account, the user will be able to log in to the device using their Azure AD credentials and will have local administrator privileges on the device.
Here are some additional things to keep in mind:
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
Sep 21 2023 05:56 AM
Thanks for the quick response, @LeonPavesic! I'll test the process and get back to you.
Sep 25 2023 08:56 PM
Sep 25 2023 08:57 PM
Sep 25 2023 11:19 PM
Hi @Abdullah_Ollivierre and @Louis_H440,
@Abdullah_Ollivierre you are right, there is no way to link an existing local admin account to an AD account in Intune without using a third-party solution, unless you have an on-premises Active Directory environment and you can use Azure AD Connect to synchronize the local admin account to Azure AD (on-prem to cloud)
If you do not have an on-premises Active Directory environment, or if you do not want to use Azure AD Connect, then you will need to use a third-party tool to link the local admin account to the AD account.
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
Sep 25 2023 11:29 PM - edited Sep 26 2023 01:33 AM
What is the rationale behind linking existing local admin account for enrolled device in the first place? Users should ideally not be given any admin privileges. If they need the elevation then consider using privilege management tools to do so.
Sep 26 2023 12:45 AM
@rahuljindal-MVP Seems people are discussing several different scenarios in this thread. Our specific use case however is migrating from another MDM to Intune. When users' devices are deregistered from the old MDM their accounts are converted to local accounts on the machine.
As for a general reason you may want to allow users to have local admin accounts, small company with large proportion of developers who you want to allow some flexibility when it comes to the tools they use
Sep 26 2023 03:54 AM