Intune Autopilot profile user is standard, but its added to the Admin group

Kostas Backas 1 Reputation point
2022-04-01T18:40:30.08+00:00

hello,

I have noticed this in Windows 11 devices. We have setup the Autopilot profile to create Standard users. This works in Win 10 devices, but in Win 11, the user that enrolls the device is added to the Local Admin groups automatically.

Any way to prevent this?

Βest regards

Kostas

Windows Autopilot
Windows Autopilot
A collection of Microsoft technologies used to set up and pre-configure new devices and to reset, repurpose, and recover devices.
411 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,733 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 43,721 Reputation points Microsoft Vendor
    2022-04-04T01:15:20.987+00:00

    @Kostas Backas ,For our issue, please confirm if any other policies which add user to admin group are deployed to the device. Meanwhile, we can test on some more windows 11 devices to see if it have the same issue.

    To remove the user from the device, we can use LocalUsersAndGroups CSP to remove the member. Here is a link for the reference:
    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Kostas Backas 1 Reputation point
    2022-04-04T06:55:00.743+00:00

    Thank you very much for your answer. There are no other policies. Windows 10 computes deployed using the same method did not have this kind of behavior (Autopilot creates standard users).

    Best regards

    Kostas