Skip to content
English
  • There are no suggestions because the search field is empty.

Minimize Local Administrators [CHK-1165]

This check verifies if users are automatically added to the local administrators group on their device when they register it in Entra ID.

Rationale

Administrative rights allow users to change all settings of the computer and install software, including malware. This poses significant risks as an individual user can be easily deceived into allowing their endpoint to be controlled by an external attacker.

Fix

An automated fix is available through Attic.

Manual steps:

  1. Navigate to Entra ID portal at https://entra.microsoft.com
  2. Go to Devices > All Devices > Device Settings
  3. Check if the setting "Registering user is added as local administrator on the device during Microsoft Entra join (preview)" is disabled
  4. Under "Local administrator settings", set "Enable Microsoft Entra Local Administrator Password Solution (LAPS)" to "Yes" if using LAPS
  5. Set "Additional local administrators on all Microsoft Entra joined devices" to add specific users or groups who should have local admin rights
  6. Do not add regular users to this list
  7. Click "Save"

Impact

Users can no longer install software at their discretion and may find this obstructive. Therefore, good communication about the reasons for this change is advisable.

More Information