Skip to content

Commit bfabed6

Browse files
Merge pull request #253491 from MicrosoftGuyJFlo/patch-67
Update assign-local-admin.md
2 parents 28005d6 + 5b940d8 commit bfabed6

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

articles/active-directory/devices/assign-local-admin.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,12 +25,15 @@ This article explains how the local administrators membership update works and h
2525

2626
## How it works
2727

28-
When you connect a Windows device with Microsoft Entra ID using a Microsoft Entra join, Microsoft Entra ID adds the following security principals to the local administrators group on the device:
28+
At the time of Microsoft Entra join, we add the following security principals to the local administrators group on the device:
2929

3030
- The Microsoft Entra Global Administrator role
3131
- The Azure AD Joined Device Local Administrator role
3232
- The user performing the Microsoft Entra join
3333

34+
> [!NOTE]
35+
> This is done during the join operation only. If an administrator makes changes after this point they will need to update the group membership on the device.
36+
3437
By adding Microsoft Entra roles to the local administrators group, you can update the users that can manage a device anytime in Microsoft Entra ID without modifying anything on the device. Microsoft Entra ID also adds the Azure AD Joined Device Local Administrator role to the local administrators group to support the principle of least privilege (PoLP). In addition to users with the Global Administrator role, you can also enable users that have been *only* assigned the Azure AD Joined Device Local Administrator role to manage a device.
3538

3639
## Manage the Global Administrator role

0 commit comments

Comments
 (0)