Additional Local Administrators on Azure AD Joined devices with Privileged Identity Management (PIM)
Back in May 2021, I had published a blog post on setting local admin account using different options available in Intune . While the methods covered in the post still hold up, there is another option available natively in Azure that can be used to setup additional local administrators on Azure AD joined devices. The option involves using Additional local administrators on all Azure AD joined devices feature in Azure which I didn't cover at the time because of its limitations. Primary limitation being that the user accounts added as additional local admin, also get added to all AAD joined devices. However, while exploring alternatives to a LAPS like solution for a customer recently, I stumbled upon Azure AD role Azure AD Joined Device Local Administrator. The possibility of using it together with Privileged Identity Management (PIM) within Additional local administrators on all Azure AD joined devices feature intrigued me and I just had to try it out. Why Azu...