Shared Local Admin Accounts for Devices

Are we allowed to have Shared Local Admin Accounts on Devices for support purposes?

The answer ideally would be NO, however, pragmatically, if you don't have a centralised directory platform (Active Directory, AzureAD and similar) its very difficult not to have and use local admin accounts, therefore, creating many of them for a team of admins is somewhat difficult across many devices.

Ideally, you will use "LAPS" or similar, which will create a centrally managed, ever-changing, unique local admin password per device, this makes management easy and secure. AzureAD devices can work with NO LOCAL ACCOUNTS leaving an AzureAD known admin account/group of accounts, with "sort of" local admin access.

If none of these options are available, you can have a local admin account on a device, which is then unique to that device (not the same on all devices) which can then be shared securely (suggest password vault) with a team of known and secure staff, support staff.