We have a Windows 2012 AD domain.
We have added some new Windows 10 Pro systems to our domain and are having an issue where when a domain user (non-admin) logs into the machine, they are automatically made a local administrator. Their account does not show up in the local Administrators group nor is there a place where we can see the user when logged in as an admin to be able to change them to a standard user.
The machines have been joined to the domain while logged in as a local admin and using the credentials of a domain admin. The first time the credentials of the domain user are used is when their account logs in for the first time after the machine was already a member of the domain.
Any ideas?
This is what it looks like when you go to settings while logged in as the user (last name and domain blacked out):