Using GPOs to add accounts or groups to the local admin group

On Sept. 18 someone asked you if you could use GPOs to add accounts or groups to the local administrators group on the local workstations, as well as change the local administrator's password. Your response was "Nope." Were you just referring to the changing of the administrator account password? I'm using a GPO to change/add who is a member of the local admins group on the local workstation.
I was obviously not very clear in that answer! Thanks for pinging me on that. Yes, there is currently no direct way to manage the administrator passwords via group policy. However, you can manage the membership of the administrators group (or any other group) on the machines. This is done in the group policies' Computer Configuration ->Windows Settings -> Security Settings -> Restricted Groups. From here you can configure a group, the members allowed to be in the group and minimally to which groups the group is allowed to belong. Be very careful about making such policy changes in the default domain policy and the domain controllers policy! You could inadvertently lock yourself out of the machines and cause some real chaos. I would suggest creating a new organizational unit for the machines you want to control and then applying the policy there.
This was first published in December 2002

Dig Deeper



Find more PRO+ content and other member only offers, here.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.



Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:









  • Virtual desktop security guide

    To secure virtual desktops, consider antivirus, certificates and network vulnerabilities. Just remember, VDI doesn't always ...

  • Guide to low-cost desktop virtualization

    In this guide, learn to virtualize desktops without spending more than you would when deploying PCs, and what VDI vendors are ...

  • VDI pilot project guide

    A VDI pilot project should start with a VDI project plan. Know what pitfalls to avoid and test product options to achieve a ...