Configure Workstation Users as Local Admins Using AD Groups

Posted by on Dec 12, 2012 in Tech Tip | 5 comments


Share The Love!
Get new article alerts!

You want to make it so a set of users in an Active Directory (AD) group are local admins.


This solution will make the users in the given AD group the local admin of any workstation. You could use this solution to make certain people only admins of their own workstation, but that would involve one AD group per workstation.

  1. Create the AD global security group "Local Computer Admins".
  2. Ensure you group your computers by server vs. workstation. For SBS sites, you'll see this in MyBusiness\Computers\SBSComputers and MyBusiness\Computers\SBSServers. Alternatively, you could use AD groups containing the computers to control how the GPO is applied, but we'll use an OU.
  3. Start the Group Policy Management MMC.
  4. In the OU MyBusiness\Computers\SBSComputers (notice we are only using this GPO for workstations, not servers, to be safe), create a new GPO named "Local Computer Admins".
  5. Edit the new Local Computer Admins GPO. For this GPO, we'll be modifying the Computer Configuration so that the Administrators local group includes the Local Computer Admins group.
  6. Navigate to Computer Configuration\Policies\Windows Settings\Restricted Groups.
  7. Right-click Restricted Groups and click Add Group. Enter Administrators and click Ok.
  8. The Properties window will appear. Here is where we will add the AD group. Click on Add in Members of this group.
  9. The group window will appear. Click Browse and then find the Local Computer Admins group in AD. Click Ok.
  10. When you return to the Properties window, you should see the AD group in the Members of this Group field. Click Ok.
  11. Close the Group Policy Management Editor window to save your changes.

You're done! Now just add users to the Local Computer Admins AD group and they will be admins on local workstations. You can use this technique for a number of local administrative capabilities, e.g., enabling RDP access for admins and non-admins, etc.


5 Responses to “Configure Workstation Users as Local Admins Using AD Groups”

  1. Right here is the right blog for everyone who wants to find out about this
    topic. You know so much its almost hard to argue with you (not that I
    really would want to…HaHa). You certainly put a fresh spin on
    a subject which has been discussed for years. Great stuff, just great!

  2. Asking questions are really pleasant thing if you are not understanding anything fully, except this
    post presents nice understanding even.

  3. Wow! At last I got a blog from where I be capable of really
    obtain helpful facts concerning my study and knowledge.

  4. If some one wants expert view concerning running a blog afterward i suggest him/her to visit this blog, Keep up the good job.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>