Skip to content

Commit b948266

Browse files
authored
Merge pull request #4846 from rodrigooliani/patch-3
Limitations for local Remote desktop Users group
2 parents 6a8b4f1 + c0bffc7 commit b948266

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

intune/intune-service/protect/endpoint-security-account-protection-policy.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,9 @@ Use the *Local user group membership* profile to manage the users that are membe
7474
> [!TIP]
7575
> To learn more about support for managing administrator privileges using Microsoft Entra groups, see [Manage administrator privileges using Microsoft Entra groups](/azure/active-directory/devices/assign-local-admin#manage-administrator-privileges-using-microsoft-entra-groups-preview) in the Microsoft Entra documentation.
7676
77+
> [!NOTE]
78+
> Microsoft Entra groups deployed to a device with this policy don't apply to remote desktop connections. To control remote desktop permissions for Microsoft Entra joined devices, you need to add the individual user's SID to the appropriate group.
79+
7780
### Configure the profile
7881

7982
Use the *Local user group membership* profile mto manage the local group membership on devices through the Windows [Policy CSP - LocalUsersAndGroups](/windows/client-management/mdm/policy-csp-localusersandgroups?WT.mc_id=Portal-fx). The CSP documentation includes more details on how configurations apply, and an FAQ about the use of the CSP.

0 commit comments

Comments
 (0)