Ask the Expert

Can I add domain groups to the local admin group through group policy?

I administer 1,200+ desktop computers running Win XP Pro. I want to know if there is a way to add domain groups to the local administrators group through group policy. I figured out how to manually add the groups to the local computer, but with hundreds of systems this can take weeks. FYI, we are running SMS and I noticed that it has added itself to the local admin group. The reason for this is there are several software programs that need local administrator rights in order to function properly. On any given computer, there are several dozen users that use the computer, and to add each user locally as a local admin is not a suitable option. As for security, we are running software called Deep Freeze. This software removes any changes and software added to the system when restarted.

Requires Free Membership to View

Yes, there is a way. Create a Group Policy Object (GPO) that runs a WMI script as a logon script. The WMI script would then add the domain group to the local Administrators group. For examples of WMI scripts that you can use to create your own, see the TechNet Script Center at

This was first published in January 2004

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: