


If it is Azure AD join device, Azure Global Administrators and Device Owner have local administrator rights by default.Īzure AD allow to define local administrators in device level. if it’s a workgroup environment, another user with local administrator privileges will need to add additional users to Administrators group. If it’s a device in on-premise Active Directory environment, either domain admin or enterprise will need to add it to Administrators group. I am sure every engineer knows how “ Local Administrators” works in a device.
