Global Administrator in Microsoft 365 or Microsoft Entra does not automatically give local administrator rights on a Windows PC. That is why the Office install is prompting for elevation.
For Office installation, the PC must have a local administrator available. If the signed-in account is not a local admin, when User Account Control appears, an account that already has administrator rights on that computer must enter its credentials.
Supported ways to grant local admin on a Microsoft Entra joined device are:
- Manually elevate the user on that specific device
- This requires an account that is already a member of the local Administrators group on that PC.
- On Windows 10 1709 and later:
- Go to Settings > Accounts > Other users
- Select Add a work or school user
- Enter the user principal name
- Set Account type to Administrator
- Use the command line on the device
- This also requires existing local admin rights.
- For Microsoft Entra ID users:
-
net localgroup administrators /add "AzureAD\<UserUPN>"
-
- For synced on-premises AD users:
-
net localgroup administrators /add "<domain>\<username>"
-
- If no account on the PC already has local admin rights
- The Office install cannot be elevated by Entra or Microsoft 365 role assignment alone.
- A local admin must be provided on the device, or the device must be reprovisioned so an administrator is available during setup.
To verify whether the current Windows account is already an administrator:
- Open Control Panel
- Go to User Accounts > Change your account type
- Confirm whether Administrator is selected
If the device is joined to a domain, use:
- Control Panel > User Accounts > Change your account type > Properties > Group Membership
- Confirm whether Administrator is selected
For the specific issue described, the missing setting is not in the Microsoft 365 admin center role assignment itself. The required change is membership in the local Administrators group on the PC.