Home › Active Directory users and groups › Step 9
Managing group membership with Restricted Groups
Step 9 of 9 in Active Directory users and groups · video 2:37
What you will learn
- Where the Restricted Groups setting lives in a GPO
- Controlling local and AD DS group membership from Group Policy
- How unlisted members are removed at policy refresh
- What happens to memberships when the GPO is unlinked
About this lesson
Keeping local group membership right on hundreds of computers by hand is slow and error-prone. This lesson presents the Restricted Groups setting in Group Policy, found under Computer Configuration, Policies, Windows Settings, Security Settings. It sets the membership of local groups on domain-joined computers, for instance putting a global group into every workstation's local Administrators group. Linked to the OU that holds the domain controllers, the same setting controls membership of AD DS groups, and it can also nest groups, within the usual nesting rules. It exists only in domain Group Policy, not in local policy. The key behaviour is enforcement: members not on the list are removed at the next Group Policy refresh, which suits Domain Admins, Enterprise Admins and local Administrators. The built-in local Administrator account is never removed, and unlinking the GPO or deleting the entry leaves the memberships it created in place until someone changes them manually.
Check yourself
1. Where in the Group Policy Management Editor is the Restricted Groups setting?
Under Computer Configuration, Policies, Windows Settings, Security Settings. It is a computer setting because it controls groups on the computers the GPO applies to, and it is empty until you add groups to it.
2. Someone manually adds their own account to Domain Admins, which is controlled by a Restricted Groups policy. What happens?
At the next Group Policy refresh the account is removed, because Restricted Groups takes out any member that is not on its list. That is why the setting suits high-level administrative groups.
3. What must the GPO be linked to for Restricted Groups to manage membership of AD DS domain groups?
The OU that holds the domain controllers' computer accounts. Domain group membership is stored on the domain controllers, so the policy has to apply to them.
4. You unlink the GPO that put a global group into every server's local Administrators group. Is the global group removed from those groups?
No. Unlinking the GPO, or deleting the Restricted Groups entry, leaves the memberships it created in place. You have to remove them manually.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.