Skip to content

Commit

Permalink
Merge pull request #163974 from mzmaili/patch-13
Browse files Browse the repository at this point in the history
Updated Azure AD device administrator role name
  • Loading branch information
PRMerger10 authored Jun 29, 2021
2 parents ae8f462 + 75c003a commit 60735f9
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions articles/active-directory/devices/assign-local-admin.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,10 +28,10 @@ This article explains how the local administrators membership update works and h
When you connect a Windows device with Azure AD using an Azure AD join, Azure AD adds the following security principals to the local administrators group on the device:

- The Azure AD global administrator role
- The Azure AD device administrator role
- The Azure AD joined device local administrator role
- The user performing the Azure AD join

By adding Azure AD roles to the local administrators group, you can update the users that can manage a device anytime in Azure AD without modifying anything on the device. Azure AD also adds the Azure AD device administrator role to the local administrators group to support the principle of least privilege (PoLP). In addition to the global administrators, you can also enable users that have been *only* assigned the device administrator role to manage a device.
By adding Azure AD roles to the local administrators group, you can update the users that can manage a device anytime in Azure AD without modifying anything on the device. Azure AD also adds the Azure AD joined device local administrator role to the local administrators group to support the principle of least privilege (PoLP). In addition to the global administrators, you can also enable users that have been *only* assigned the device administrator role to manage a device.

## Manage the global administrators role

Expand Down

0 comments on commit 60735f9

Please sign in to comment.