Hi protokos ,
Thanks for post here.
After reading your post I understand that you want to restrict local account log into computer .
If I misunderstand please let me know.
Based on my knowledge , this chosen list can’t be removed after domain joined, but you may like to edit computer local security policy to achieve the goal
:
1.
log in computer with local administrator account.
2.
Perform “gpedit.msc” to open group policy editor.
3.
Navigate to :computer configuration /windows settings/security settings/local policies/User Right assignment
4.
Edit policy “Deny log on locally” to add all the local account in it.
5.
Modify the password of local administrator account .
Please notice that this policy is not applied to local administrator account.
Hope that’s helpful.
Tiger Li
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.