How to create a local admin via Intune

Поділитися
Вставка
  • Опубліковано 4 жов 2024
  • Take a look at how you can create a local admin via Intune.
    On my demo I used a custom configuration profile with the 2 OMA-URI strings below:
    ./Device/Vendor/MSFT/Accounts/Users/Admin5/Password
    ./Device/Vendor/MSFT/Accounts/Users/Admin5/LocalUserGroup
    I hope you enjoy and thanks for watching
    Jackson Felden

КОМЕНТАРІ • 48

  • @robmoore3007
    @robmoore3007 3 роки тому +3

    Thank you! Very helpful. Now just need to switch users that are Admin to Non-Local admins

  • @jangonda4837
    @jangonda4837 2 роки тому +6

    Hi Jackson, it worked very well thank you for you video. Just one question do you know how to add one more thing "set password never expire" via intune?
    Looking forward to hearing from you.
    Thanks

  • @asamshafique6734
    @asamshafique6734 3 роки тому +2

    Brilliant Video.
    Loved it.

  • @brad8084
    @brad8084 2 роки тому +2

    Thank you for the video. Trying it out now, but, looks promising.

    • @jacksonfeldencloudsecurity
      @jacksonfeldencloudsecurity  2 роки тому

      Great, good luck!!!

    • @jacksonfeldencloudsecurity
      @jacksonfeldencloudsecurity  2 роки тому

      and thanks for watching :)

    • @brad8084
      @brad8084 2 роки тому

      @@jacksonfeldencloudsecurity It worked. You saved the day with a remote user and I could not elevate the session in screenconnect with our 365 Admin. Luckily they were in endpoint manager and this worked. Thank you again

  • @bradrichards9005
    @bradrichards9005 2 роки тому +1

    This was EXCELLENT! Thank you!

  • @flexmundl3858
    @flexmundl3858 2 роки тому

    Thanks Jackson, excellent video, Appreciate the knowledge share... 🤝

  • @navinkalkhair8666
    @navinkalkhair8666 2 роки тому +4

    Thanks for details information. We have created the same & its working fine...but on portal its showing error i.e. -2016281112 (remediation failed). Can you help me on this.

  • @dineshravichandran8506
    @dineshravichandran8506 2 роки тому +3

    Hey Jackson, this is exactly the video i've been looking for and thank you for sharing your knowledge! this works except it runs into an error, have you been able to solve it?

  • @texddiaz
    @texddiaz Рік тому +1

    grat video! thanks for share!

  • @Rideables
    @Rideables 11 місяців тому

    Amazing! Straight and to the point, just what I was looking for! I'm subscribed!
    While user was created, do you know why the status might be "Error" and error code "-2016281112" for both the LUG and Password when I assign it to a group of Users for each of user's machines? Should it be assigned to devices instead?

  • @richardmascarenhas3445
    @richardmascarenhas3445 2 роки тому +2

    great video, just wanted to ask if we local admin password in the configuartion profile at a later stage will it update each of the machines thsat the local admin user is deployed?

  • @bolaiphone3645
    @bolaiphone3645 2 роки тому +1

    Thank you! This was really helpful.
    Could I ask how do you make the local admin password not expire?

  • @kierandineen8323
    @kierandineen8323 Рік тому +1

    Thanks for that

  • @CallmeFabrice
    @CallmeFabrice 3 роки тому +3

    Hi thanks for your video. Now how to remove this admin account ? Is there anyway to put an aad cloud account in local administrator group ?

    • @jacksonfeldencloudsecurity
      @jacksonfeldencloudsecurity  3 роки тому +1

      I'm glad you liked it, thanks for the feedback.
      To remove the user I did the following:
      1 - I Unassigned the configuration policy to create my admin5
      2 - I created a PowerShell script called "RemoveAdmin5.ps1" with the following line:
      Remove-LocalUser -Name "Admin5"
      3 - from "Endpoint Manager / Devices / Scripts" I assigned the RemoveAdmin5.ps1 to my devices
      After some time Admin5 was removed from my devices

  • @unkownuser2320
    @unkownuser2320 Рік тому

    Please let us know what are ways to create local administrator on Intune managed devices may be during autopilot etc it is possible to use Account protection section for creating local admin accounts, how to provide admin access for logged on users

  • @ashokm4845
    @ashokm4845 Рік тому

    Thank you for sharing. Question. How can I delete this account. I can see when I have to give local admin access to a user/pc just to do something, but once done, I would like to delete this.

  • @unkownuser2320
    @unkownuser2320 Рік тому

    Kindly share some other method to get local administrator access like provide local admin access to help desk for Autopilot provisioned machines

  • @ppetrix
    @ppetrix 2 роки тому +2

    Thank you. But what about setting password never expires ?

    • @timtursic387
      @timtursic387 Рік тому

      Did you get the answer? I'm looking now how can I disabled changing password at first login.

    • @ppetrix
      @ppetrix Рік тому

      @@timtursic387 no, i see a comment down that said is not posible with OMA URI. Strange becouse it could be so simple.

  • @Happ13rAbroad
    @Happ13rAbroad Рік тому

    How would one accomplish this for MacOS that is enrolled in Intune?

  • @TheTori619
    @TheTori619 2 роки тому +1

    Hey Jackson nice video, I've did exactly the same steps you've done in this video everything worked fine but when you look at the Profile assignment status you'll receive Error Instead of Succeeded!
    Also how can I create the user with "Password Never Expires"

    • @mohamadzib825
      @mohamadzib825 Рік тому

      Did you get solution , I run same issue

    • @TheTori619
      @TheTori619 Рік тому

      @@mohamadzib825 just use a script and deploy the script to the devices... the OMA URI way wont make it NEVER EXPIRE.

  • @ProEagle01
    @ProEagle01 Рік тому

    Thank you, like others here I am getting the 0x8 error. however, if i check the device I did see the account was created and i was able to login. something I noticed was if I looked at the member of that new admin account. it was not part of any member groups. I did add administrators as the group but was wondering about this. I would have thought it would of set that for you.

  • @chebrets
    @chebrets 5 місяців тому

    how to create admin account using this method but without the password?

  • @christophercass5713
    @christophercass5713 2 роки тому

    How about using Azure Local Admin role instead? No OMI to deploy. Need to configure Endpoint security to prompt to secure desktop credentials for standard and admin users. You can even use PIM, but it is not perfect. Target a user with a group and assign that group the Local Admin role. They will have admin on all devices in your Intune. Then you can remove/disable all Administrative accounts and use PIM for a more secure setup.

    • @bradscott952
      @bradscott952 2 роки тому

      thats how I set it up and works great! the only problem I ran into is when you have to apply a fresh start command to an intune win10 device it fails because there's no local admin account enabled. To get around this I use the method in this video with a long complex password. This meets the need of OOBE and fresh start, and still allows me the ability using Azure elevated privileges to make changes as an azure admin

    • @jacksonfeldencloudsecurity
      @jacksonfeldencloudsecurity  2 роки тому

      Thanks for the input Christopher and Brad. I created the video to solve the problem when a local admin is needed by 3rd party applications running on devices, but is always good to keep your eye for other options too.

  • @CheekyCake
    @CheekyCake 2 роки тому

    Hi! Can I set this local account to lose data everytime when someone log out?

  • @michaelanthonyilos7869
    @michaelanthonyilos7869 2 роки тому

    Hello Jackson, Thanks for your video! It helps me to create local admin but i'm having this error "ERROR CODE
    0x87d1fde8" do you know how to remdiate it? it seems that local admin is working It just bothering to see error

  • @RamanLodhi-ii1xe
    @RamanLodhi-ii1xe Рік тому

    How can you add user to remote desktop users group?

  • @professor3095
    @professor3095 2 роки тому

    Very thanks but i get setting error 0x87d1fde8. It has created the user and add it to local admin.

  • @mohamedmoez00
    @mohamedmoez00 Рік тому

    Hi Jackson!
    I need the password to be Never Expired.

  • @mohamadzib825
    @mohamadzib825 Рік тому +1

    I get error 0x8

  • @mtcnousa356
    @mtcnousa356 Рік тому

    please share the string here

  • @nuxthrou
    @nuxthrou Рік тому

    how to hash the password?