Home › Active Directory users and groups › Step 9

Managing group membership with Restricted Groups

Step 9 of 9 in Active Directory users and groups · video 2:37

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Keeping local group membership right on hundreds of computers by hand is slow and error-prone. This lesson presents the Restricted Groups setting in Group Policy, found under Computer Configuration, Policies, Windows Settings, Security Settings. It sets the membership of local groups on domain-joined computers, for instance putting a global group into every workstation's local Administrators group. Linked to the OU that holds the domain controllers, the same setting controls membership of AD DS groups, and it can also nest groups, within the usual nesting rules. It exists only in domain Group Policy, not in local policy. The key behaviour is enforcement: members not on the list are removed at the next Group Policy refresh, which suits Domain Admins, Enterprise Admins and local Administrators. The built-in local Administrator account is never removed, and unlinking the GPO or deleting the entry leaves the memberships it created in place until someone changes them manually.

Good to know: only the Members of this group list removes members who are not listed; the This group is a member of option only adds. Group Policy Preferences (Local Users and Groups) can add members without replacing the whole list.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Where in the Group Policy Management Editor is the Restricted Groups setting?

Under Computer Configuration, Policies, Windows Settings, Security Settings. It is a computer setting because it controls groups on the computers the GPO applies to, and it is empty until you add groups to it.

2. Someone manually adds their own account to Domain Admins, which is controlled by a Restricted Groups policy. What happens?

At the next Group Policy refresh the account is removed, because Restricted Groups takes out any member that is not on its list. That is why the setting suits high-level administrative groups.

3. What must the GPO be linked to for Restricted Groups to manage membership of AD DS domain groups?

The OU that holds the domain controllers' computer accounts. Domain group membership is stored on the domain controllers, so the policy has to apply to them.

4. You unlink the GPO that put a global group into every server's local Administrators group. Is the global group removed from those groups?

No. Unlinking the GPO, or deleting the Restricted Groups entry, leaves the memberships it created in place. You have to remove them manually.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Groups, Computers and OUs

4.5★ · 1,445 students on Udemy

See the course on Udemy
← Special identities in Windows and AD DSPath complete - back to Active Directory users and groups →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.