Ran our first local admin audit in two years. half the company has local admin on their own machine.
Didn't plan to look at this. was troubleshooting a software install issue for a user and noticed they had local admin. checked a few others. then pulled a full report.
47 percent of our endpoints have the primary user in the local administrators group. some of them i can trace back to specific requests. most i can't. they've just been there.
the security team flagged local admin proliferation in our last risk assessment. i said we'd look into it. that was eight months ago.
the problem with cleaning it up is that nobody documented why anyone got it. so removing it means either breaking something silently and waiting for the ticket, or asking every affected user what they actually need it for which is 160 conversations i don't have time for.
we're on intune so the technical fix is straightforward. the operational fix is not. every time i've tried to scope a remediation plan it stalls because there's no clean way to know what breaks without just doing it and finding out.
has someone done a local admin remediation at this scale without it turning into a month of helpdesk tickets.