So we have a PC that is Azure-joined, not AD, not standalone. Domain admin is obvious. And we can set PC-local admin using domain admin. But how do we give an Azure user local admin rights? Well, the simplest is in administrative Powershell:
net localgroup Administrators /add "AzureAD\userupn@domain.com"
where userupn@domain.com is the UPN of the user, the user’s login into Azure/365. Note that the text AzureAD
is not the domain name, it is literal characters as you see it here. In other words, a breakage of historical syntax!