My manager wants to know which users have local admin rights on the workstation for audit purpose, but SCCM doesn't have this build in function. Thanks for the internet, here is an article on how to get this working:
Basically here is steps:
- Import a custom MOF file as new hardware inventory class;
- Import a CAB file as a new Compliance Settings and deploy to the collection you want to monitor ( I used all workstation collection);
And how you can use it?
Just build a query from Attribute class – Local Group Members.