Accidentally Removed LocalAdmin group in Active Directory

Vicky Carlson - Repair 20 Reputation points
2024-01-24T17:56:53.4866667+00:00

I meant to remove local admin rights from a security group on our domain controller, but I think I deleted the builtin localadmin group. Nobody has localadmin rights now, including administrators.

Computer Configuration -> Preferences -> Control Panel Settings -> Local Users and Groups

New -> Local Group New Local Group Properties

  • Action: Update
  • Group name: Administrators (built-in)
  • Delete all member users: Checked this box.
  • Delete all member groups: Checked this box.

  I thought I was adding my security group, but in the “Members” section I typed in localadmin rather than the security group name. This has removed local admin rights on all devices.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 36,261 Reputation points Moderator
    2024-01-24T20:25:28.59+00:00

    Hi @Vicky Carlson - Repair

    You can use the same Group Policy Preference setting to add the Builtin Local Admin in the local administrator group.

    When you check Delete all members user and groups in Group policy Preference , you have to add all groups and accounts should have local administrator permission, Otherwise all accounts will be deleted from local administrator group.

    Please don't forget to accept helpful answer

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.