SOLVED

Azure AD user in Windows 10 - local admin problem

%3CLINGO-SUB%20id%3D%22lingo-sub-168747%22%20slang%3D%22en-US%22%3EAzure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-168747%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20have%20Office%20365%20Business%20Essentials%20and%20Premium%20licenses%2C%20we%20do%20not%20have%20AAD%20Premium%2C%20EMS%2C%20Intune%20licenses.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20I%20login%20to%20a%20new%20PC%20using%20some%20users%20(not%20O365%20admin%20user%20account)%20O365%20credentials%2C%20this%20user%20becomes%20a%20local%20admin%20in%20that%20PC.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBut%20if%20I%20use%20some%20other%20user's%20O365%20credentials%20(not%20O365%20admin%20user%20account)%20to%20login%20to%20that%20same%20PC%2C%20this%20second%20user%20that%20log's%20in%20to%20the%20same%20PC%20is%20not%20a%20local%20admin.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%2C%20I%20can't%20find%20anywhere%20on%20that%20PC%20to%20change%20this.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22%22%3EHow%20do%20I%20control%20which%20(O365)%26nbsp%3Buser%20account%20is%20local%20admin%20and%20which%20is%20not%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-168747%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-389761%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389761%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1743%22%20target%3D%22_blank%22%3E%40Harry%20Dubois%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20having%20similar%20experience%20with%20the%20delay%20between%20adding%20a%20user%20in%20Azure%20Device%20Settings%20(local%20Admin)%20and%20the%20time%20it%20actually%20reflects%20on%20the%20other%20end.%3C%2FP%3E%3CP%3EAccording%20to%20MS%2C%20privilege%20updates%20can%20only%20work%20if%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20user%20is%20signed%20off%3C%2FP%3E%3CP%3E-%20after%204h%20when%20a%20new%20Primary%20Refresh%20Token%20is%20issued.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20definitely%20tell%20that%20it%20takes%20way%20longer%20than%204h.%20My%20test%20user%20has%20currently%20local%20admin%20rights%20(assigned%20a%20few%20weeks%20ago)%20and%20it%20works%20as%20expected.%20However%2C%20I've%20removed%20these%20privileges%20approx%2015h%20ago%20and%20the%20users%20appears%20to%20have%20still%20admin%20rights.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20is%20perhaps%20better%20practice%2C%20but%20I'm%20seriously%20questioning%20how%20practical%20this%20feature%20is%20if%20it%20takes%20so%20long%20update%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268163%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268163%22%20slang%3D%22en-US%22%3EYes%2C%20but%20not%20directly.%20We%20waited%20for%20a%20day%20or%20so%20and%20then%20it%20worked.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268161%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268161%22%20slang%3D%22en-US%22%3E%3CP%3EDid%20you%20set%20this%20at%20AAD%20-%26gt%3B%20Devices%20-%26gt%3B%20Device%20Settings%20-%26gt%3B%20Additional%20local%20administrators...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBe%20aware%20that%20this%20added%20user%20account%20is%20now%20local%20admin%20in%20all%20pc's.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267339%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267339%22%20slang%3D%22en-US%22%3EProblem%20is%20solved.%20We%20have%20added%20the%20user%20as%20local%20administrator%20in%20the%20Intune%20portal.%20Worked%20after%2024%20hours%2C%20maybe%20due%20to%20sync%20from%20Intune.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-265650%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-265650%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20first%20user%20that%20signs%20in%20on%20Windows%2010%20automatically%20becomes%20a%20local%20admin.%20Alle%20users%20after%20that%20will%20be%20standard%20users%2C%20unless%20they%20are%20an%20admin%20in%20Office%20365.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20believe%20that%20without%20Azure%20AD%20Premium%20licenses%2C%20you%20cannot%20add%20extra%20local%20admins%20from%20the%20management%20panels%20in%20Office%20365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20when%20you%20sign%20in%20to%20a%20Windows%20computer%20as%20user%20with%20Administrator%20privileges%2C%20you%20can%20add%20other%20users%20and%20assign%20the%20admin%20rights%20on%20that%20computer.%20To%20do%20this%2C%20go%20to%20the%20settings%20panel%20%26gt%3B%20Accounts%20%26gt%3B%20Other%20People.%20There%20you%20see%20the%20other%20users%20(or%20add%20them)%20and%20can%20change%20the%20account%20type%20from%20standard%20user%20to%20administrator.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-265629%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-265629%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1743%22%20target%3D%22_blank%22%3E%40Harry%20Dubois%3C%2FA%3E%3CBR%20%2F%3ESorry%20but%20I%20didnt%20understand.%20No%20luck%20in%20what%3F%20What%20are%20you%20trying%20to%20accomplish%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-265626%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-265626%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9466%22%20target%3D%22_blank%22%3E%40Salvatore%20Biscari%3C%2FA%3E%3C%2FP%3E%3CP%3EI%20have%20add%20the%20user%20as%20a%20local%20admin%20but%20no%20luck.%20Any%20ideas%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-172879%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-172879%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ELike%20I%20said%2C%26nbsp%3B%3CSPAN%3Ewe%20do%20not%20have%20AAD%20Premium%2C%20EMS%2C%20Intune%20licenses.%20Those%20steps%20require%20EMS%20licenses%20or%20AAD%20Premium.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EI%20was%20able%20to%20set%20the%20secondary%20login%20account%20as%20admin%20account.%20Login%20using%20this%20secondary%20account%2C%20go%20to%20Control%20Panel%2FUser%20Accounts%2FUser%20Accounts%2FChange%20your%20account%20type%20and%20use%20O365%20admin%20account%20or%20the%20first%20account%20used%20to%20login%20to%20PC%20to%20go%20past%20UAC.%20This%20way%20you%20can%20upgrade%20user%20account%20as%20local%20admin.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EBased%20on%20this%20link%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.spiceworks.com%2Ftopic%2F1580701-azure-ad-users-given-local-admin-permissions%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcommunity.spiceworks.com%2Ftopic%2F1580701-azure-ad-users-given-local-admin-permissions%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Eit%20is%20not%20good%20idea%20to%20downgrade%20the%20first%20(O365)account%20used%20to%20login%20to%20PC%20as%20standard%20user.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EPrefer%20to%20use%20O365%20admin%20account%20or%20some%20other%20O365%20account%20used%20as%20local%20admin%20account%20when%20login%20the%20first%20time%20to%20PC%20and%20add%20the%20actual%20user%20account%20to%20PC%20after%20this.%20This%20way%20normal%20users%20do%20not%20have%20local%20admin%20permissions%20and%20you%20dont%20have%20to%20downgrade%20user%20account%20permissions.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-169377%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-169377%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20a%20look%20at%20this%20article%3A%26nbsp%3B%3CA%20href%3D%22http%3A%2F%2Fwww.rebeladmin.com%2F2017%2F12%2Fstep-step-guide-add-additional-local-administrators-azure-ad-joined-devices%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fwww.rebeladmin.com%2F2017%2F12%2Fstep-step-guide-add-additional-local-administrators-azure-ad-joined-devices%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EDoes%20it%20help%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1449564%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20user%20in%20Windows%2010%20-%20local%20admin%20problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1449564%22%20slang%3D%22en-US%22%3E%3CP%3EHere's%20a%20Microsoft%20document%20that%20I%20think%20is%20relevant%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fassign-local-admin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fassign-local-admin%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hi

 

We have Office 365 Business Essentials and Premium licenses, we do not have AAD Premium, EMS, Intune licenses.

 

If I login to a new PC using some users (not O365 admin user account) O365 credentials, this user becomes a local admin in that PC.

 

But if I use some other user's O365 credentials (not O365 admin user account) to login to that same PC, this second user that log's in to the same PC is not a local admin.

 

Also, I can't find anywhere on that PC to change this.

 

How do I control which (O365) user account is local admin and which is not?

10 Replies
Highlighted
Best Response confirmed by Iivo Kerminen (Contributor)
Solution

Hi

 

Like I said, we do not have AAD Premium, EMS, Intune licenses. Those steps require EMS licenses or AAD Premium.

 

I was able to set the secondary login account as admin account. Login using this secondary account, go to Control Panel/User Accounts/User Accounts/Change your account type and use O365 admin account or the first account used to login to PC to go past UAC. This way you can upgrade user account as local admin.

 

Based on this link

https://community.spiceworks.com/topic/1580701-azure-ad-users-given-local-admin-permissions

it is not good idea to downgrade the first (O365)account used to login to PC as standard user. 

Prefer to use O365 admin account or some other O365 account used as local admin account when login the first time to PC and add the actual user account to PC after this. This way normal users do not have local admin permissions and you dont have to downgrade user account permissions.

Highlighted

@Salvatore Biscari

I have add the user as a local admin but no luck. Any ideas?

Highlighted
@Harry Dubois
Sorry but I didnt understand. No luck in what? What are you trying to accomplish?
Highlighted

The first user that signs in on Windows 10 automatically becomes a local admin. Alle users after that will be standard users, unless they are an admin in Office 365. 

 

I believe that without Azure AD Premium licenses, you cannot add extra local admins from the management panels in Office 365.

 

However, when you sign in to a Windows computer as user with Administrator privileges, you can add other users and assign the admin rights on that computer. To do this, go to the settings panel > Accounts > Other People. There you see the other users (or add them) and can change the account type from standard user to administrator. 

Highlighted
Problem is solved. We have added the user as local administrator in the Intune portal. Worked after 24 hours, maybe due to sync from Intune.
Highlighted

Did you set this at AAD -> Devices -> Device Settings -> Additional local administrators...

 

Be aware that this added user account is now local admin in all pc's.

Highlighted
Yes, but not directly. We waited for a day or so and then it worked.
Highlighted

@Harry Dubois 

 

I'm having similar experience with the delay between adding a user in Azure Device Settings (local Admin) and the time it actually reflects on the other end.

According to MS, privilege updates can only work if:

 

- user is signed off

- after 4h when a new Primary Refresh Token is issued.

 

I can definitely tell that it takes way longer than 4h. My test user has currently local admin rights (assigned a few weeks ago) and it works as expected. However, I've removed these privileges approx 15h ago and the users appears to have still admin rights.

 

It is perhaps better practice, but I'm seriously questioning how practical this feature is if it takes so long update?

 

Highlighted