How to create a local admin via Intune

preview_player
Показать описание
Take a look at how you can create a local admin via Intune.

On my demo I used a custom configuration profile with the 2 OMA-URI strings below:

./Device/Vendor/MSFT/Accounts/Users/Admin5/Password
./Device/Vendor/MSFT/Accounts/Users/Admin5/LocalUserGroup

I hope you enjoy and thanks for watching
Jackson Felden
Рекомендации по теме
Комментарии
Автор

Thanks Jackson, excellent video, Appreciate the knowledge share... 🤝

flexmundl
Автор

Thank you! Very helpful. Now just need to switch users that are Admin to Non-Local admins

robmoore
Автор

Hi Jackson, it worked very well thank you for you video. Just one question do you know how to add one more thing "set password never expire" via intune?
Looking forward to hearing from you.

Thanks

jangonda
Автор

Thank you for the video. Trying it out now, but, looks promising.

brad
Автор

Hey Jackson, this is exactly the video i've been looking for and thank you for sharing your knowledge! this works except it runs into an error, have you been able to solve it?

dineshravichandran
Автор

Thanks for details information. We have created the same & its working fine...but on portal its showing error i.e. -2016281112 (remediation failed). Can you help me on this.

navinkalkhair
Автор

Thank you! This was really helpful.
Could I ask how do you make the local admin password not expire?

bolaiphone
Автор

Amazing! Straight and to the point, just what I was looking for! I'm subscribed!
While user was created, do you know why the status might be "Error" and error code "-2016281112" for both the LUG and Password when I assign it to a group of Users for each of user's machines? Should it be assigned to devices instead?

Rideables
Автор

great video, just wanted to ask if we local admin password in the configuartion profile at a later stage will it update each of the machines thsat the local admin user is deployed?

richardmascarenhas
Автор

Please let us know what are ways to create local administrator on Intune managed devices may be during autopilot etc it is possible to use Account protection section for creating local admin accounts, how to provide admin access for logged on users

unkownuser
Автор

Thank you, like others here I am getting the 0x8 error. however, if i check the device I did see the account was created and i was able to login. something I noticed was if I looked at the member of that new admin account. it was not part of any member groups. I did add administrators as the group but was wondering about this. I would have thought it would of set that for you.

ProEagle
Автор

Thank you for sharing. Question. How can I delete this account. I can see when I have to give local admin access to a user/pc just to do something, but once done, I would like to delete this.

ashokm
Автор

Kindly share some other method to get local administrator access like provide local admin access to help desk for Autopilot provisioned machines

unkownuser
Автор

Hi! Can I set this local account to lose data everytime when someone log out?

CheekyCake
Автор

Hi thanks for your video. Now how to remove this admin account ? Is there anyway to put an aad cloud account in local administrator group ?

CallmeFabrice
Автор

How would one accomplish this for MacOS that is enrolled in Intune?

HapprAbroad
Автор

Hello Jackson, Thanks for your video! It helps me to create local admin but i'm having this error "ERROR CODE
0x87d1fde8" do you know how to remdiate it? it seems that local admin is working It just bothering to see error

michaelanthonyilos
Автор

How can you add user to remote desktop users group?

RamanLodhi-iixe
Автор

Very thanks but i get setting error 0x87d1fde8. It has created the user and add it to local admin.

professor
Автор

How about using Azure Local Admin role instead? No OMI to deploy. Need to configure Endpoint security to prompt to secure desktop credentials for standard and admin users. You can even use PIM, but it is not perfect. Target a user with a group and assign that group the Local Admin role. They will have admin on all devices in your Intune. Then you can remove/disable all Administrative accounts and use PIM for a more secure setup.

christophercass