After SAML SSO & DUO integration with AD authentication we wish to remove a common Local admin account which was previously setup in each of our client's dashboards. The admin access level in now determined by Groups in AD so having the common local admin account is a security risk. Attempts to delete or demote the account yield "You cannot revoke access to the only organization admin". We have SAML administrative roles configured with the appropriate AD groups. Access via DUo/SAML is working with the admin roles desired but having the common local admin account still active is a security risk even it is 2fa enabled.
... View more