Your Azure AD tenant contoso.com should prevent users from being automatically added to the local Administrators group when they join their Windows 11 device. Which setting should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Device settings in Azure AD.
Why this is the answer
The correct answer is Device settings in Azure AD. Within Azure AD, you can configure the "Additional local administrators on Azure AD joined devices" setting. By default, the user performing the join operation is added to the local Administrators group. To prevent this, you can set this option to "None" or specify a different group of users who are allowed to be local administrators. Windows Autopilot is used for device provisioning and deployment, not for controlling local administrator rights after a device is joined. Provisioning packages are for configuring devices with specific settings, but the direct control over local administrators during an Azure AD join is handled by Azure AD device settings. Security defaults in Azure AD enforce baseline security policies like MFA, but do not control local administrator assignments on joined devices.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed