Configure a policy of local group admins in a lab Intune
Creating an Endpoint Security/Account Protection
Policy
By default, I wanted the "Administrators" group on the devices to include the "technicians" group, so I created this policy in "Endpoint Security > Account Protection".
I selected the "platform" as Windows and the "profile" as Local user group membership.
I named the policy.
I clicked on "Add" and then on "Select users/group" to select the group I want to add to the local admin group on the devices.
I selected "GRP-IT".
I left the "Scope tags" as default.
Then, I selected the dynamic group that includes all devices with the "FRLAB" category.
Finally, I clicked on Save!