Grant and Revoke admin rights through Domain Controller

Admin can provide one-time admin access to multiple domain-joined devices from the Domain controller. With the admin rights, devices can be enrolled over-the-air via .ppkg file. Once the devices are enrolled, domain Admin can revoke the device user’s admin access and trigger a restart for all the devices from MDM.

A. Grant Admin rights to the device users from Domain Controller
  1. Log in to Domain controller as a Domain Administrator.
  2. From the start menu go to Windows Administrative Tools > Active Directory Users and Computers.
  3. To grant Admin permissions to non-admin users:
    1. Navigate to Users, select Domain Users, right click and select Add to a group…

    2. In the Select Groups popup, in the Enter the object names to select text box, enter Domain Admins.

    3. Click Check Names to verify and click OK.
Now, all the users under Domain Users group get Admin rights. For the changes to take effect, restart the user’s device. From the user’s device, you can verify if the user got Admin right by navigating to Access Work or School > Your Info.

B. Perform user-initiated enrollment
  1. Open Firefox or any other supported browser, and in the address bar, enter enrollment URL. For example, https://mdmserver.demo.com.
  2. Enter valid AD credentials to authenticate.

  3. Once the authentication is successful, the user can download .ppkg file by clicking OK > Yes > Yes, add it in the subsequent screens.

C. Revoke Admin rights of the user from the Domain Controller
  1. Log in to Domain controller as a Domain Administrator
  2. From the start menu go to Windows Administrative Tools > Active Directory Users and Computers.
  3. To revoke Admin permissions from the domain user:
    1. Navigate to Users, double click Domain Admins.
    2. Go to Members tab, select Domain Users, click Remove, and click Yes to confirm.

    3. Click Apply > OK.

      Now, Admin rights are revoked from all the users under Domain Users group. For the changes to take effect, restart the user’s device from MDM. From the user’s device, you can verify if the user got Admin right by navigating to Access Work or School > Your Info.

      Now, the user can manage the device through MDM without Admin rights. Work or school account will still be present, for non-admin user. However, only Admin can unenroll the device from MDM.