Windows
Local admin assignment did not apply when added as a group
The requested admin access did not take effect when the users were added as a group. The configuration was changed so each account was added individually, then it synced and worked as local admin.
Killed once by someone from XL.net, on 2026-05-05.
What you see
- Requests to run something as administrator did not work until the admin configuration finished syncing.
- The group-based admin setup did not apply as expected.
Why it happens
Likely A policy conflict in the managed environment prevented the group-based admin assignment from applying; individual assignment was required.
When it shows up
A managed Windows device should receive local admin access from a cloud-backed policy, but the change is not taking effect after a group-based assignment.
You are in this case if:
- The admin change only becomes active after the directory sync window.
- Adding the users as a group does not work, but adding each account individually does.
1 fix below
The steps that killed it
The steps are behind a quick check
There are two ways in and both take a few seconds. Signing in opens the steps on every bug page; so does reading the picture.
Or answer this
Drawing a picture for you.
Can't read it? Sign in instead.
Someone from XL.net killed this on a Windows computer on 2026-05-05. It is written up from that one repair, so it cites no outside page.