By default only the person who joined the computer to Azure AD is granted local administrator rights. Adding someone as a 'primary user' in Intune does not grant them local admin access on the workstation. To add someone as local administrator on the machine that is joined to Azure AD, follow these steps:
net localgroup Administrators UWINAD\{uwinid} /add