# Local Administrators Group Policy: 4 Ways to Control Admin Rights

Source: https://srvscripts.com/guides/local-administrators-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Local administrators Group Policy settings let you decide, from one place, which users and groups belong to the local Administrators group on every domain-joined workstation and server. Without them, admin rights pile up: a helpdesk technician adds a user “for one day”, an installer adds a service account, and nobody removes them. This guide compares Restricted Groups, Group Policy Preferences (GPP) and Intune, shows the per-computer admin group pattern, and covers verification, troubleshooting and rollback.

**Short answer:** Create a GPO linked to the workstation OU, go to `Computer Configuration » Preferences » Control Panel Settings » Local Users and Groups`, add a **Local Group** item for **Administrators (built-in)** with action Update, and add your admin group with **Add to this group**. Run `gpupdate /force` and check with `net localgroup administrators`. Tick “Delete all member users” and “Delete all member groups” only when you want the GPO to own the whole membership.

In short: Create a GPO linked to the workstation OU, go to Computer Configuration » Preferences » Control Panel Settings » Local Users and Groups, add a Local Group item for Administrators (built-in) with action Update, and add your admin group with Add to this group.

## Which method to use

All the local administrators Group Policy options below change the same local group, but they differ in one key point: whether they add members or replace the membership.

| Method | Behaviour | Scope | Pros | Cons |
| --- | --- | --- | --- | --- |
| Restricted Groups: “Members of this group” | Replaces the whole membership | Computer | Simple, strict, reapplied regularly | No merge between GPOs; easy to remove accounts you still need |
| Restricted Groups: “This group is a member of” | Adds a group, never removes | Computer | Safe, merges across GPOs | Does not clean up extra members |
| GPP Local Users and Groups (Update) | Adds or removes named members | Computer or user | Variables such as %ComputerName%, item-level targeting | Needs care with the delete options |
| GPP with “Delete all member users/groups” | Clears members, then adds the listed ones | Computer | Replace behaviour with targeting | Removes anything not listed on every refresh |
| Intune Account protection / LocalUsersAndGroups CSP | Add (Update), Remove (Update) or Add (Replace) | Device | Works for Microsoft Entra joined devices | Conflicts with Restricted Groups; one policy per device |

For most domains we recommend GPP with the Update action, plus a separate cleanup step when you are ready to enforce an exact list. Use Windows LAPS for the built-in Administrator password; the methods here control membership, not passwords.

## Prerequisites

Check these before you build any local administrators Group Policy object:

- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain. Intune Account protection needs Windows 10 20H2 or later or Windows 11.

- Rights to create and link GPOs, the Group Policy Management Console and, for the per-computer pattern, the Active Directory PowerShell module.

- Security groups for admins, for example CONTOSO\Workstation Admins and CONTOSO\Server Admins. Never add individual user accounts to a GPO.

- A test OU with one workstation and one member server. Note the current members first: `net localgroup administrators`.

## Method 1: Restricted Groups

Restricted Groups is the oldest local administrators Group Policy feature. It lives at `Computer Configuration » Policies » Windows Settings » Security Settings » Restricted Groups`. It is only available in domain GPOs, not in the local policy editor. It is processed by the Security settings extension, which reapplies security policy every 16 hours even when the GPO has not changed, so manual changes are reverted.

### Option A: “This group is a member of” (additive)

- Create a GPO linked to the workstation OU, for example SEC – Workstation Local Admins, and edit it.

- Right-click **Restricted Groups** and choose **Add Group…**. Enter the domain group, for example `CONTOSO\Workstation Admins`.

- In the **This group is a member of** section click **Add…** and type `Administrators`.

- Click **OK**, run `gpupdate /force` on a test machine and check the membership.

Only inclusion is enforced. If you later remove the entry, Windows does not take the group back out of Administrators. Several GPOs can use this option for the same local group and the results add up.

### Option B: “Members of this group” (replace)

- Right-click **Restricted Groups**, choose **Add Group…** and enter `Administrators`.

- In **Members of this group** add every account that must stay: the built-in `Administrator` account, `CONTOSO\Domain Admins` and your admin groups.

- Click **OK** and test on one machine before you link it widely.

Microsoft documents this list as exact: everyone listed is kept and everyone missing is removed. An empty list removes all members. If two GPOs set “Members of this group” for Administrators, they do not merge; the GPO that wins precedence sets the whole list. The settings are stored in `GptTmpl.inf` under `\\contoso.com\SYSVOL\contoso.com\Policies\{GPO-GUID}\Machine\Microsoft\Windows NT\SecEdit`:

```
[Group Membership]
*S-1-5-32-544__Memberof =
*S-1-5-32-544__Members = *S-1-5-21-...-512,*S-1-5-21-...-1105
```

`S-1-5-32-544` is the well-known SID of the local Administrators group, so the setting works on any language version of Windows.

## Method 2: Group Policy Preferences Local Users and Groups

GPP is the most flexible local administrators Group Policy method. The item lives at `Computer Configuration » Preferences » Control Panel Settings » Local Users and Groups`.

### Add an admin group (Update)

- Right-click **Local Users and Groups** and choose **New » Local Group**.

- Set **Action** to Update. Microsoft describes Update as changing only the settings defined in the item and leaving everything else as it was.

- In **Group name** select **Administrators (built-in)** from the drop-down. This uses the well-known SID, not the localised name.

- Under **Members** click **Add…**, enter `CONTOSO\Workstation Admins`, keep the action **Add to this group** and click **OK**.

- Leave **Delete all member users** and **Delete all member groups** cleared for now.

To remove a known account from every machine, add it to the same item with **Remove from this group**. This is how you clean up an old support account without touching anything else.

### Update vs Replace for Local Group items

| Action | Effect on the local group | Use it? |
| --- | --- | --- |
| Create | Creates the group if it does not exist | For custom local groups only |
| Update | Adds or removes the listed members; creates the group if missing | Yes, for Administrators |
| Replace | Deletes the group and creates a new one with a new SID | Never for built-in groups |
| Delete | Deletes the local group | Only for custom groups |

### Enforce an exact membership

When you are ready to strip unknown admins, edit the same item and tick **Delete all member users** and **Delete all member groups**. On each refresh GPP removes all user and group members, then adds the members listed in the item. Before you enable it:

- List every account that must stay: `CONTOSO\Domain Admins`, your admin groups, the built-in `Administrator` account (Windows does not allow it to be removed) and any account that Windows LAPS manages.

- Check servers for service accounts or backup agents that were made local admins, and add them to a server-specific GPO first.

- On Microsoft Entra hybrid joined devices, the Global Administrator and Microsoft Entra Joined Device Local Administrator role SIDs are added at join time. Decide whether they should stay and list them if so.

## Method 3: Per-computer admin groups with %ComputerName%

Sometimes one user must be admin on one PC only, for example a developer workstation. Instead of editing the GPO for each request, create one domain group per computer and let GPP resolve the name on each machine.

- Create an OU such as `OU=Local Admin Groups,OU=Groups,DC=contoso,DC=com` and create the groups with a short prefix:

```
Import-Module ActiveDirectory$ou  = 'OU=Workstations,DC=contoso,DC=com'$grp = 'OU=Local Admin Groups,OU=Groups,DC=contoso,DC=com'Get-ADComputer -Filter * -SearchBase $ou | ForEach-Object {    $name = 'LA-' + $_.Name    if (-not (Get-ADGroup -Filter "Name -eq '$name'")) {        New-ADGroup -Name $name -SamAccountName $name -GroupScope Global `            -GroupCategory Security -Path $grp `            -Description "Local administrators on $($_.Name)"    }}
```

- In the GPP Local Group item for **Administrators (built-in)**, click **Add…** under Members and type `CONTOSO\LA-%ComputerName%`. Press F3 in the field to pick the variable from the list instead of typing it.

- Keep the action **Add to this group**. On each computer, GPP replaces `%ComputerName%` with the local name, so PC-0142 receives `CONTOSO\LA-PC-0142`.

- To grant rights, add the user to the matching group. The user signs out and in again to receive the new token.

If a group does not exist for a computer, the member cannot be resolved and the item logs a warning, so run the creation script on a schedule or as part of your build process. Combine this with Delete all member users only after every machine has its group.

## Method 4: Intune Account protection and the LocalUsersAndGroups CSP

For Microsoft Entra joined or co-managed devices, use Intune instead of a local administrators Group Policy object.

- In the Intune admin center go to **Endpoint security » Account protection » Create Policy**, platform **Windows**, profile **Local user group membership**.

- Pick **Administrators** in **Local group**. The list offers six built-in groups.

- Choose the **Group and user action**: Add (Update) adds members, Remove (Update) removes named members, and Add (Replace) replaces the membership like Restricted Groups.

- Set **User selection type** to Users (Entra users and groups, Entra joined devices only) or Manual (username, domain\username or SID; also for hybrid joined devices).

The profile uses the `./Device/Vendor/MSFT/Policy/Config/LocalUsersAndGroups/Configure` setting. As a custom OMA-URI the XML looks like this; `U` means Update and `R` means Restrict (replace):

```

```

Points from Microsoft’s CSP documentation to plan around:

- Entra groups must be added by SID; Entra users use `AzureAD\user@contoso.com`.

- If Update and Replace both target the same group, Replace wins. With Replace on Administrators, add `Administrator` explicitly.

- Only one LocalUsersAndGroups policy can apply to a device, and conflicting Intune profiles are not sent at all.

- Applying this CSP and Restricted Groups to the same device gives unpredictable results. On co-managed devices, choose Intune or Group Policy for this job, not both.

- Entra groups added this way do not grant Remote Desktop sign-in on Entra joined devices; Microsoft says to add individual user SIDs for that.

## Scoping and exceptions

- **Separate GPOs for workstations and servers.** Link Workstation Admins to the workstation OU and Server Admins to the server OU. Do not link a local administrators Group Policy object to the Domain Controllers OU: domain controllers have no local SAM, so the local Administrators group there is the domain’s BUILTIN\Administrators group.

- **Item-level targeting.** On the GPP item’s **Common** tab, tick **Item-level targeting** and target by Organizational Unit, Operating System or Security Group, for example to add Lab Admins only on computers in the lab OU.

- **Security filtering.** To exclude machines, create a computer group, add it on the GPO’s **Delegation » Advanced** page and set **Apply group policy** to Deny.

## Windows LAPS and the built-in Administrator

Group membership and password management are separate jobs. Keep the built-in Administrator (or a custom managed account) in the group and let Windows LAPS rotate its password and back it up to Active Directory or Microsoft Entra ID. Windows 11 24H2 and Windows Server 2025 add automatic account management, where LAPS can create and manage the account for you. If you manage a custom account, add it to your GPP or Intune membership list so a replace action does not remove it.

## Verify it works

- Refresh and read the result on the target machine:

```
gpupdate /forcenet localgroup administratorsGet-LocalGroupMember -Group Administrators | Format-Table Name, ObjectClass, PrincipalSource
```

`Get-LocalGroupMember` can fail when the group contains orphaned SIDs from deleted accounts; `net localgroup` still works and shows them.

- Confirm the GPO applied: `gpresult /scope computer /r` must list it under Applied Group Policy Objects. For details run `gpresult /h C:\Temp\gp.html`; the report shows Restricted Groups under Security Settings and GPP items under Local Users and Groups.

- Check GPP errors in the Application log. Warnings from source Group Policy Local Users and Groups (event ID 4098) name the item and the error, for example a member that could not be resolved.

- For deeper tracing, enable **“Configure Local Users and Groups preference logging and tracing”** under `Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing`.

- Check from a management host across many machines:

```
Invoke-Command -ComputerName PC-0142, PC-0143 -ScriptBlock {    net localgroup administrators}
```

## Troubleshooting

Most local administrators Group Policy problems come from two settings fighting over the same group, or from a token that has not been refreshed.

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Admin group added, user still has no admin rights | Old access token | Sign out and in again; group changes apply at logon |
| Accounts disappear from Administrators | Restricted Groups “Members” or GPP delete options in another GPO | Search all GPOs with gpresult /h; remove the conflicting setting |
| Only one GPO’s list applies | Two GPOs use “Members of this group” | Use “This group is a member of” or GPP Update, which merge |
| Event 4098, member not resolved | Typo, missing LA-%ComputerName% group, or no DC reachable | Create the group; test name resolution with Get-ADGroup |
| Membership flips between two states | Intune LocalUsersAndGroups and Restricted Groups both apply | Keep one method per device |
| Local group renamed or SID changed | GPP action set to Replace | Use Update for built-in groups |
| Nothing applies at all | GPO linked to the user OU, or security filtering | Link to the computer OU and check Authenticated Users has Read |

## Roll back or undo

- **Restricted Groups:** removing the entry or unlinking the GPO does not restore old members. Windows keeps the membership as last set. Add back the accounts you need with a GPP Update item or manually with `net localgroup administrators CONTOSO\GroupName /add`.

- **GPP:** clear the delete options first, then change the item to remove only what you added (**Remove from this group**), let it apply, and delete the item afterwards.

- **Intune:** unassigning the profile does not revert membership. Deploy a Remove (Update) profile for the members you added.

- **Locked out of a machine:** sign in with the LAPS-managed account, or as a Domain Admin, which is the reason to always keep `Domain Admins` in replace lists.

Test every local administrators Group Policy change on a pilot OU, export the membership of a sample of machines before enforcing a replace list, and review the admin groups themselves at least quarterly.

## Local administrators Group Policy at a glance

**Official documentation:** [LocalUsersAndGroups Policy CSP](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups), [Account protection policy for endpoint security in Intune](https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-account-protection-policy), [Group Policy Preferences](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-policy/group-policy-preferences).

**Related guides:** [Set up Windows LAPS on Windows Server 2025 and Windows 11](/guides/windows-laps-setup/) · [GPO security filtering: target or exclude users and computers](/guides/group-policy-security-filtering/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### What is the difference between Members and Member Of in Restricted Groups?

“Members of this group” defines the exact membership, so anyone not listed is removed. “This group is a member of” only adds the restricted group to the named local group and never removes anything, so it is the safer choice for adding an admin group.

### Should I use Restricted Groups or Group Policy Preferences for local admins?

Use GPP Local Users and Groups with the Update action for most cases, because it merges across GPOs, supports %ComputerName% and item-level targeting. Use Restricted Groups Members only when you need a strict, simple replace list.

### Why did my admin rights not change after gpupdate?

Group membership is part of the access token created at sign-in. The user must sign out and in again, and gpresult must show the GPO as applied to the computer.

### Can I use Intune and Group Policy together to manage local administrators?

Not for the same device. Microsoft states that applying the LocalUsersAndGroups CSP and Restricted Groups together gives unpredictable results, so choose one method per device.

### Does removing a Restricted Groups policy restore the old members?

No. Windows keeps the membership as it was last set. Add back the accounts you need with a GPP Update item, Intune or net localgroup.
