This results in:
If you chose not to add local administrator, in the autopilot policy, the Azure accounts will not have local admin. But the Office 365 Global administrator will have local admin and it's password can be used when prompted for elevation.
Audit logs not enabled by default. How to enable them:
Security & Compliance Admin Center > Search & Investigation > Audit Log Search, performed a search, advised the audit log is not enabled, given the option to enable it, selected “Yes”