Intune - Local Admin Security Policy

Matt Dillon 1,211 Reputation points
2023-03-07T15:25:54.46+00:00

I am in a Hybrid Azure AD environment. I set up the Endpoint security - Account protection - Local user group membership policy in my Intune tenant to replace a GPO that would set the SCCM server and a few users and groups as members of the Administrators group. I created a security group and denied the GPO from my endpoint.

While in office or connected to VPN:

Test 1: Passed

I removed all the members of the Administrators group and did a gpupdate /force to make sure that the GPO did not repopulate. Once that was verified, I created the Intune local user group membership policy and added an extra random user as a test and did a ADCONNECT sync for good measure. (I used an Add (Replace) and Manual with the SID of all the entries) I then did a sync from Settings - Accounts - Access work or school - my account - Info. I refreshed the Administrators group and I was pleased to see all the accounts in the Intune policy show up, including the extra one.

Test 2: Fail

I removed the extra account in the policy and again did an ADCONNECT sync, and the sync on my device and the extra account was not removed.

Test 3: Fail

I then removed 3 of the accounts that were supposed to be in there and did the syncs again and even waited an hour. Unfortunately the Administrators group was not updated with the accounts that were supposed to be in there.

Questions

  1. Do I need a direct connection to the domain either via VPN or in an office for this policy to work in a Hybrid Azure AD environment?
  2. How often does the policy run? Can that be modified?
  3. While the GPO would instantly correct the members of the Administrators group, I am not seeing that with this policy. What is the expectation using this policy as my guess at this point is things happen once and that is it or they happen when the policy has accounts added, but not deleted.
  4. Is a Proactive remediation PowerShell better suited for what i am trying to do?
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,783 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,664 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Greg Hall 0 Reputation points
    2024-03-05T09:58:33.52+00:00

    Catherine is correct. But...there are multiple ways to do the same thing. Hopefully I can add a few ways of doing the same thing...I only have 5 years of Intune experience.

    1. Do I need a direct connection to the domain either via VPN or in an office for this policy to work in a Hybrid Azure AD environment? In a Hybrid Environment you can still set Control Policy Conflict...MDMwinoverGPO to No. GPO will win until you go full entra joined.

    https://video2.skills-academy.com/en-us/windows/client-management/mdm/policy-csp-controlpolicyconflict

    1. How often does the policy run? Can that be modified?

    8 Hours, there are a few ways to modify...

    First, you can also restart the Windows Intune Extension Service in Services.msc,

    Second, in the Intune console you can run a sync when you select the device,

    Third, users can run a sync through the instructions Catherine provided.

    Finally, if you want all machines to run a sync at the same time, restart the service using a script I am sure you know how to write.

    1. While the GPO would instantly correct the members of the Administrators group, I am not seeing that with this policy. What is the expectation using this policy as my guess at this point is things happen once and that is it or they happen when the policy has accounts added, but not deleted.

    You can create a custom ORA-URI. Custom GPO's. Very powerful, make sure you test.

    https://video2.skills-academy.com/en-us/mem/intune/configuration/custom-settings-windows-10

    https://video2.skills-academy.com/en-us/mem/intune/configuration/custom-settings-windows-10

    If you set ControlPolicyConflicts to allow GPO to win...this might not be necessary.

    1. Is a Proactive remediation PowerShell better suited for what i am trying to do?

    No, do not manage the local administrator groups through Proactive Remediations in Intune. You can use Proactive Remediations as the detection/remediation layer for any machine missing users in the admin group. You should deploy both.

    If you need to remove a user/group, Proactive Remediations is always the "last layer", not the managed option.

    0 comments No comments