LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

What does the Restricted Groups policy do, and what is Administrators in this context?

Restricted Groups lets a GPO define the exact membership of a local group on every targeted computer; Administrators here is the built-in local group of each machine, not a domain group.

Restricted Groups resets the local Administrators group to the GPO list

* On refresh the local group is set to exactly the GPO's list. *

Each Windows computer has a built-in local group Administrators whose members have full control of that machine. With Computer Configuration > Policies > Windows Settings > Security Settings > Restricted Groups you add that group to a GPO and list its members, for example GG_CH_Systemadmins, the helpdesk group and the local accounts labadmin and eduadm.

The important behaviour: the "Members of this group" list is authoritative. On each policy refresh the local group is set to exactly that list; anyone added by hand who is not on it is removed (the one exception is the built-in Administrator account, which is never taken out of Administrators). That is useful against admin-rights creep, but it also means that anything you forget to list (like a local break-glass account) loses its rights.

Local accounts are entered without a domain prefix (labadmin, not G001\labadmin), otherwise the policy looks for a domain account that does not exist.

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026