PC is joined to non profit domain. Unable to elevate permissions for global admin user on the pc

Konrad K 0 Reputation points
2026-10-03T18:01:55.2033333+00:00

I have set up a non profit domain. I have a number of users including the global admin user (that I used to set up a pc)
When I try to install M365 business standard on the PC, using the global admin user, it requests elevated privileges.

neither M365 admin or Entra admin appear to have a specific setting for granting local admin access

Windows for business | Windows Client for IT Pros | Devices and deployment | Set up, install, or upgrade
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-03T18:02:11.8066667+00:00

    Global Administrator in Microsoft 365 or Microsoft Entra does not automatically give local administrator rights on a Windows PC. That is why the Office install is prompting for elevation.

    For Office installation, the PC must have a local administrator available. If the signed-in account is not a local admin, when User Account Control appears, an account that already has administrator rights on that computer must enter its credentials.

    Supported ways to grant local admin on a Microsoft Entra joined device are:

    1. Manually elevate the user on that specific device
      • This requires an account that is already a member of the local Administrators group on that PC.
      • On Windows 10 1709 and later:
        • Go to Settings > Accounts > Other users
        • Select Add a work or school user
        • Enter the user principal name
        • Set Account type to Administrator
    2. Use the command line on the device
      • This also requires existing local admin rights.
      • For Microsoft Entra ID users:
        • net localgroup administrators /add "AzureAD\<UserUPN>"
      • For synced on-premises AD users:
        • net localgroup administrators /add "<domain>\<username>"
    3. If no account on the PC already has local admin rights
      • The Office install cannot be elevated by Entra or Microsoft 365 role assignment alone.
      • A local admin must be provided on the device, or the device must be reprovisioned so an administrator is available during setup.

    To verify whether the current Windows account is already an administrator:

    • Open Control Panel
    • Go to User Accounts > Change your account type
    • Confirm whether Administrator is selected

    If the device is joined to a domain, use:

    • Control Panel > User Accounts > Change your account type > Properties > Group Membership
    • Confirm whether Administrator is selected

    For the specific issue described, the missing setting is not in the Microsoft 365 admin center role assignment itself. The required change is membership in the local Administrators group on the PC.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.