Removal of Admin Rights
Identify unnecessary local admin accounts, protect critical ones with exclusion policies, and revoke the rest — manually or automatically.
Why and how to remove admin rights
Reducing unnecessary local admin accounts is one of the highest-impact steps in any endpoint hardening program.
The Admin Rights removal workflow
Removing admin rights in Endpoint Central restricts administrative privileges on endpoint devices, preventing unauthorized installation, modification, or removal of applications and reducing the risk of malware infections and credential abuse.
Selecting a computer and clicking Remove Local Admin removes all local admin accounts on that machine — except for those explicitly protected by an Exclusion Policy. After removal, a Privileged Application List can be created and associated with those devices, enabling the former admins — now running as standard users — to still elevate specific approved applications when needed.
- Identify and analyze: The Admin Rights Summary tab lists all local admin accounts found on discovered computers. The Local Admin Count column shows the number of local admin accounts per machine.
- Protect critical accounts: Add accounts that must never be removed to the Exclusion Policy before taking any action.
- Remediate: Remove the remaining unnecessary accounts either manually or automatically.
Exclusion Policy
Define which accounts are always retained, regardless of removal actions.
Protecting required admin accounts globally
The Exclusion Policy tab lets you create global policies that protect specific admin accounts. Accounts added here are retained on every computer where they are found — regardless of any manual or automatic removal action. The sysadmin can choose to protect their own account, the built-in administrator account, or any other account.

Removing Admin Rights
Choose manual removal for targeted action or automatic removal for ongoing enforcement.
Manual removal of admin rights
Once the Exclusion Policy is finalized, select the computers to modify in the Admin Rights Summary tab and click Remove Local Admin. Admin privileges for all local admin accounts on those computers will be removed during the next refresh cycle — except for those protected by the Exclusion Policy.

Automatic removal of admin rights
Enabling Automatic Removal removes all non-excluded admin accounts from the selected computer groups during the next 90-minute refresh cycle — and continues to enforce this on an ongoing basis, so new unauthorized accounts that appear are removed automatically.
