Utilize AAD Security Groups for Device "Additional Local Administrators" support
Emulating the Intune Roles method with Assignments, Members and Scopes would be ideal. Also the ability to disable Global Admin access (limit to groups/scopes added).
We’re currently working on this capability and will provide an update when it’s done.
However, instead of expanding the “Additional Local administrators” setting, we will support adding AAD groups to Windows 10 local groups (.e.g Administrators, Remote Desktop Users) via MDM policy and elevate user privileges on logon. This will provide greater flexibility to assign different groups to different devices
Andrey Brenner commented
Hi @Azure AD Team.
Any updated regarding this? Still not working in 2004
Seems the functinality is added in Windows 10 2004 https://www.inthecloud247.com/add-an-azure-ad-group-to-the-local-administrators-group-with-microsoft-intune/
Is there an update available for this feature?
Nearly 2 years and nothing has changed. What is the point of these feedbacks really?
Try this one on for size. It might just be good enough for now ...
Here is some relevant information that some might have missed:
If you want a user to be local admin on a machine, this can be accomplished through intune powershell extensions quite easily, even with checks agains an AAD group. Hit me up on twitter is this is something I should blog about, and please specify some scenario that I should target. @michael_mardahl
Agreed, please resolve this issue
Agree with Martin... please add the ability to specify which groups of devices the users have admin rights on. Giving the users admin rights on all AAD joined devices in the tenant is not viable for us.
Bill Gates commented
yes, it is dumb to have to manually add each individual user to Azure local admins, let us use security groups please
Martin Wüthrich commented
and thus there are huge organization, and they only want to have a reasonable amount of admin per device:
Please make the group assignment more finegrained, so that I can add only the Asia IT on the ASIA Devices. Maybe connect it with:
Mark Rusbridge commented
Could we expand this to adding Azure AD groups to any local group on the device?