Azure AD用户角色/组分配同步至本地及免登配置管理员权限咨询
Absolutely, you can handle this entirely through Azure AD (and its associated tools) without needing to manually log into each device. Let’s break down the best approaches for your scenario:
1. Use Azure AD’s Built-in Local Administrator Role
This is the simplest method for Azure AD-joined devices:
- Log into the Azure Portal, navigate to Azure Active Directory > Devices > Device settings
- Locate the "Additional local administrators on Azure AD joined devices" section
- Add either your two Developer users directly, or (even better) create a Developer Security Group (add the two users to this group first) and add the group here
- Once your devices are fully Azure AD joined, these users/groups will automatically be added to the local
Administratorsgroup on each device—no manual login or on-device configuration required.
2. Deploy a Configuration Profile via Intune
If you’re using Microsoft Intune (the cloud-based device management tool integrated with Azure AD), you can create a targeted policy to push local admin rights to your devices:
- Go to the Intune portal, navigate to Devices > Configuration profiles
- Create a new profile for Windows 10 and later, select the Settings catalog template
- Search for "Local Users and Groups" in the settings picker, then select the Add local group members setting
- Set the target local group to
Administrators, then add your Developer users or their security group to the member list - Assign this profile to your 3 devices (you can target them via an Azure AD device group if you’ve set one up)
- Intune will sync this policy to the devices automatically in the background—no user login is needed to apply the changes.
What About Traditional Group Policy (GPO)?
Since you don’t have an on-premises Active Directory environment, traditional GPO won’t work here—it depends on on-prem AD infrastructure to distribute policies. However, Intune’s configuration profiles serve as a cloud-native replacement for GPO, giving you the same level of control over device settings without requiring local AD.
Quick Tip for Unjoined Devices
If your devices haven’t been Azure AD joined yet, complete that process first (you can do this remotely or during the initial device setup). Once joined, the methods above will take effect automatically.
内容的提问来源于stack exchange,提问作者Brenden Kehren

