Skip to content

Manage Local Administrators with Microsoft Intune

Manage Local Administrators with Microsoft Intune

Intune can manage membership of built-in Windows local groups through an Endpoint security Account protection policy. This is preferable to manually adding administrators on individual devices.

  1. Open the Microsoft Intune admin center.
  2. Go to Endpoint security > Account protection.
  3. Create a policy for Windows 10 and later using the current Account protection profile.
  4. Configure Local user group membership.
  5. Select the local Administrators group and choose the appropriate action. Add (Update) adds specified members without removing existing members; Add (Replace) replaces membership and should be used with extra care.
  6. Select the Microsoft Entra users or groups that require the role, assign the policy to the intended device scope, then monitor deployment status.

Keep local administrator membership as limited as possible and use a controlled group rather than granting privileges individually where practical.