Skip to content
Best Method to Add a Local User to Local Administrator Group with Intune Local User Membership Policy

Best Method to Add a Local User to Local Administrator Group with Intune Local User Membership Policy

Written By Vaishnav K
Last Updated August 23, 2024
Posted In Intune
SHARE

In this article, I will explain how to Local User to Local Administrator Group with Intune local user membership policy. Adding a local user to the Local Administrator group via Intune using the Account Protection profile is a streamlined and secure method to manage user privileges on Windows devices. Microsoft recommends a solution called LAPS for managing local admin users, groups, and passwords automatically on Windows devices.

Account Protection is part of Intune’s broader Endpoint Security suite, allowing IT administrators to enforce security policies, including managing local group memberships. By leveraging this feature, administrators can ensure that specific users or groups are added to the Local Administrators group on managed devices, helping to balance security with the necessary administrative access. Create local user using the following Best Guide To Create A Local User With Intune Remediation Script.

An administrator can create a new “Account protection” profile within Intune to implement this. This profile is configured under “Endpoint security” and includes settings that allow adding or removing users from local groups. By specifying the local administrator group and designating the user or group to be added, Intune automatically applies this configuration to the targeted devices. This approach minimizes the need for manual intervention or custom scripting, making it easier to manage and enforce across large environments.

Using Account Protection to manage local administrator rights is particularly beneficial in environments with strict security requirements. It ensures that only authorized users have elevated privileges while reducing the risk of unauthorized access or changes.

Patch My PC
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 1
Add a Local User to Local Administrator Group with Intune Local User Membership Policy. Fig. 1

Key Reasons to Add a Local User to Local Administrator Group

Adding a local user to the local administrator group is done for several vital reasons, each granting the user certain privileges and responsibilities in the system. Here are the key reasons:

Key ReasonsDetails
Administrative PrivilegesSystem Configuration: The user can change system settings, install software, and manage system resources. This includes modifying system files, configuring network settings, and installing or removing programs.
User Management: The user can create, modify, and delete other user accounts on the machine, as well as manage permissions and group memberships.
Security ManagementSystem Troubleshooting: The user has the authority to troubleshoot and fix various issues that may arise, including resolving software conflicts, system crashes, and hardware issues.
Updates and Patches: The user can apply operating system updates and patches, which is crucial for maintaining the system’s security and stability.
Troubleshooting and MaintenanceFile System Control: The user can access, modify, and delete any files or folders on the system, regardless of their ownership or permissions. This is essential for backup, recovery, and system management tasks.
Resource Management: The user can manage and allocate system resources like disk space, memory, and CPU usage, ensuring the system runs efficiently.
Full Access to Files and ResourcesSome applications and system updates require administrative privileges to be installed or configured properly. Adding a user to the local administrator group allows them to perform these tasks without needing to log in as a different user or temporarily use elevated permissions.
Required for Certain Software InstallationsSome applications and system updates require administrative privileges to be installed or configured properly. Adding a user to the local administrator group allows them to perform these tasks without needing to log in as a different user or use elevated permissions temporarily.
Remote ManagementIf the system needs to be managed remotely, being a member of the local administrator group often allows for remote desktop connections, remote management tools, and other remote administration tasks.
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Table. 1

Additionally, the method integrates seamlessly with other Intune security policies, allowing for a unified approach to endpoint protection. By automating and centralizing the management of local administrator accounts, organizations can enhance their security posture and ensure compliance with internal and external security standards.

Account Protection Policy to Add a Local User to Local Administrator Group

Follow the below-mentioned steps to create an Account Protection Policy to Add a Local User to Local Administrator Group with Intune. Log In to the Microsoft Intune Admin Center using your administrator credentials.

  • Navigate to Endpoint Security  Account Protection
  • Click on +Create Policy
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 2
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 2

In the next step, we can create a new Account Protection Policy from scratch. For that, give the options mentioned below.

  • Platform: Windows 10 and later
  • Profile: Local user group membership

Note! Local user group membership policies help to add, remove, or replace members of local groups on Windows devices.

Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 3
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 3

On the Basics details page, we can name the Local user group membership Account Protection policy Add HTMDAdm1n to Local Administrator Group”. If needed, provide a brief policy description and click Next.

Add a Local User to Local Administrator Group with Intune Local User Membership PolicyFig. 4
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 4

Configuration settings page under the Local Users And Groups option. Select the below-mentioned options

  • Local group: Administrators
  • Group and user action: Add (Update)
  • User selection type: Manual
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 5
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 5

Once you click Add user(s) in the above screenshot, you will see an option to mention the Username. Here, we mention our Local User, HTMDAdm1n, and hit the OK button.

Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 6
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 6

On the next tab,  leave the scope tags Default. If you have any custom scope tag available, you can also select it for this deployment.

Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 7
Add a Local User to Local Administrator Group with Intune Local User Membership Policy Fig. 7

Under the Assignments tab, click Include Groups and select HTMD – Test ComputersThe filter and Filter mode options should be kept as they are. In this assignment, there is no need to choose to Exclude any groups.

Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 8
Add a Local User to Local Administrator Group with Intune Local User Membership Policy. Fig. 8

On the Review + Add tab, carefully review all your settings for “Add a Local User to Local Administrator Group” policy. Once you’ve confirmed everything is correct, select “Create” to implement the changes.

Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 9
Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 9

Monitor Add a Local User to Local Administrator Group Policy

This Account Protection policy has been deployed to the Microsoft Entra ID group (HTMD – Test Computers). The policy will take effect as soon as possible once the device is synced. You can also initiate a manual sync from the targeted machine or the Intune Portal.

To monitor the policy deployment status from the Intune Portal, follow the steps below.

Navigate to Endpoint Security > Account protection. Search for the “Add HTMDAdm1n to Local Administrator Group” policy. The deployment status for this policy can be seen under the Device and user check-in status.

Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 10
Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 10

End User Experience – Add a Local User to Local Administrator Group Policy

Now, we must check whether the Account Protection Local user group membership policy worked. To check the same. Log in to one of the policy-targeted devices.

Open Run and type lusrmgr.msc under Local Users and Groups (Local). Click on Users and select HTMDAdm1n. Right-click and go to Properties > Member Of. Now, the Administrators group has been added successfully.

Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 11
Best Method to Add a Local User to Local Administrator Group with Intune. Fig. 11

Author

Vaishnav K has over 10+ years of experience in SCCM, Device Management, and Automation Solutions. He writes and imparts his knowledge about Microsoft Intune, Azure, PowerShell scripting, and automation. Check out his profile on LinkedIn.

Written by

Vaishnav K has over 12+ years of experience in SCCM, Modern Device Management, and Automation Solutions. He writes and imparts his knowledge about Microsoft Intune, Windows 365, Azure, PowerShell scripting and automations. LinkedIn Profile : https://www.linkedin.com/in/vaishnav-k-957b0589/

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read