If you need to disable local Administrator account, change/set password or create new local Admin/user you can review previously article about GPO approach.
GPO - How to create local Administrator account using Group policies
http://www.alessandromazzanti.com/2017/04/gpo-how-to-create-local-administrator.html
Otherwise you can do that using SCCM.
Summarizing you would need to create a simple CI checking on specific collection verifyng thereshold relatively devices that have local Administrator account enabled, apply remediation (account disabling) and finally have available reports/alerts.
Here it is more verbosely article:
https://4sysops.com/archives/disable-the-local-administrator-account-with-sccm/