Is there a way to remove admin rights from mac devices using intune?

Ammar Esmaeel 5 Reputation points
2023-02-13T08:35:14.24+00:00

Hello all,

I was wondering if there is a way to remove admin rights from mac users's devices enrolled in our intune,

I know there is no function to do so but is there a script i can push with intune agent?

Thank you

Microsoft Intune MacOs
Microsoft Intune MacOs
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.MacOs: A family of Apple operating systems for the Apple Mac line of computers.
76 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,646 questions
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,366 Reputation points
    2023-02-14T01:12:36.1466667+00:00

    @Ammar Esmaeel Thanks for posting in our Q&A.

    Honestly, I'm not familiar with scripts on Mac. For this issue, I have done a lot of research and I found that someone has shared a script to remove admin right on Mac. Please refer to the following links:

    https://community.jamf.com/t5/jamf-nation/script-to-remove-admin-right-on-mac/m-p/260730

    https://www.hexnode.com/mobile-device-management/help/script-to-revoke-give-admin-rights-to-standard-user-in-mac/

    Note: Non-Microsoft link, just for the reference.

    Hope it will help.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Selcuk Beyhan 0 Reputation points
    2024-06-28T09:59:01.7733333+00:00

    What I understand with the whole onboarding journey is:

    1. You install the device MAC or Windows doesnt matter and the device asks for an intial user
    2. the first user created is always admin (local or works/school user - doesnt matter)
    3. you do the onboarding to intune is (either during installation or manually - doesnt matter)
    4. you have to create a second user (work/school user) with standard user rights
      1. this is the user that the person is supposed to use

    So in this flow, the first user facilitating the onboarding cannot be the real user. Either you use a local user with username/password you keep secure or you use a Device Enrolment Manager account.

    Then you create the second account as standard user.

    I hope my approach is meaningful.

    Thanks.

    0 comments No comments