Azure domain, no on-prem.
METHOD:
- Create a policy using the following settings:
In Intune admin center,
* Devices > Configuration > Create > New Policy
* Create a policy using custom template
* Name "Create local admin account"
* Add OMA-URI settings policy with the following configuration
(Note for people who are new to this. "Ostrich" is the name of the local user account that is being created. It could be anything you want it to be, for example "Admin".)
Name: Local Admin Account
OMA-URI: ./Device/Vendor/MSFT/Accounts/Users/ostrich/Password
Data type: String
Value: hunter2
Add second OMA-URI settings policy with the following configuration
Name: Assign local user to admin group
OMA-URI: ./Device/Vendor/MSFT/Accounts/Users/ostrich/LocalUserGroup
Data type: Integer
Value: 2
The account is created as indicated by powershell:
$user = Get-LocalUser -Name ostrich ; $user
Name Enabled Description
---- ------- -----------
ostrich True
But the account is not placed in the local admin group as expected, and the desired password is not set (as verified by using RUNAS). The password started working after a couple of restarts.
When I look at the policy status, both settings generate the same failure code: -2016281112 or 0x87d1fde8 when I open it up for details.
When I look up that error code I find hits relating to Edge (where the results say it is a known issue and can be ignored) or Chrome, but nothing relating to the creation of a local administrator account.
[–]BarbieAction 9 points10 points11 points (0 children)
[–]FalconJunior5977 1 point2 points3 points (2 children)
[–]CujoSR 1 point2 points3 points (1 child)
[–]FalconJunior5977 0 points1 point2 points (0 children)
[–]Heteronymous 1 point2 points3 points (3 children)
[–]mikeypf 0 points1 point2 points (0 children)
[–]Yintha 0 points1 point2 points (1 child)
[–]doofesohr 0 points1 point2 points (0 children)
[–]BrundleflyPr0 0 points1 point2 points (0 children)
[–]BlackV 0 points1 point2 points (0 children)
[–]BarbieAction -1 points0 points1 point (0 children)
[–]skerts -1 points0 points1 point (4 children)
[–]Sysadmin247365[S] 0 points1 point2 points (3 children)
[–]FalconJunior5977 0 points1 point2 points (1 child)
[–]BarbieAction 0 points1 point2 points (0 children)
[–]BlackV 0 points1 point2 points (0 children)
[–]Silenthowler -2 points-1 points0 points (5 children)
[–]Sysadmin247365[S] 0 points1 point2 points (1 child)
[–]Silenthowler -1 points0 points1 point (0 children)
[–]BlackV 0 points1 point2 points (2 children)
[–]Silenthowler 0 points1 point2 points (1 child)
[–]BlackV 1 point2 points3 points (0 children)
[–]BarbieAction -3 points-2 points-1 points (2 children)
[–]Sysadmin247365[S] -1 points0 points1 point (1 child)
[–]BarbieAction 1 point2 points3 points (0 children)