Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Group Policy Restricted Groups can enforce membership in local groups on domain-joined Windows computers, but its Members list acts as a replacement: members not listed are removed. Before deploying it for local Administrators, inventory the membership and decide whether replacement is what you intend. For Windows 10 version 20H2 and later, Microsoft recommends the LocalUsersAndGroups policy instead.

What Restricted Groups does—and what it does not do

Restricted Groups is a Group Policy security setting for controlling security-sensitive group membership. Microsoft says it should be used primarily to configure local groups on workstations or member servers. It can place a domain account or domain group into a local group, such as local Administrators, but it is not a way to manage the members of that domain group itself. For domain-group membership, use the appropriate Active Directory group-management process.

Microsoft describes Restricted Groups as designed specifically for local groups. See Policy CSP – RestrictedGroups and Description of Group Policy Restricted Groups.

Understand Members versus Member Of

Members: define who belongs to the restricted group

When you configure a group’s Members list, Group Policy ensures that the listed accounts and groups are members of the restricted group. It also removes current members that are not listed. Microsoft states: “When a Restricted Groups Policy is enforced, any current member of a restricted group that isn’t on the Members list is removed.” That makes the setting a replacement-style control, not an add-only list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For example, if the local Administrators group currently contains a help-desk domain group and a locally managed support account, but the policy lists only the help-desk group, the support account can be removed when policy applies. The built-in Administrator account is a narrow exception: it cannot be removed from the built-in Administrators group. Do not assume other current members are protected from removal.

Member Of: ensure the restricted group belongs elsewhere

The traditional Group Policy Restricted Groups interface also has a Member Of concept. It ensures that the restricted group is a member of other groups; it is different from defining which accounts belong to the restricted group. Microsoft’s RestrictedGroups Policy CSP documentation notes that its CSP implementation does not provide MemberOf functionality, so capabilities are not identical across every interface or policy implementation.

Choose the right policy for the Windows version and management context

Option Membership effect Scope and guidance
Restricted Groups The configured Members list adds listed members and removes current members not listed. Primarily for local groups on workstations or member servers. Microsoft lists the RestrictedGroups CSP for Windows 10 version 1803 and later, and recommends LocalUsersAndGroups instead beginning with Windows 10 version 20H2.
LocalUsersAndGroups Update adds and/or removes specified members while leaving unspecified members alone. Replace removes unspecified members. Applies to Windows 10 version 20H2 and later. Use it instead of Restricted Groups for local group configuration on those versions, in line with Microsoft’s recommendation.
Group Policy Preferences: Local Users and Groups Can create, modify, or delete local users and groups. A preference may be changed by users and is reapplied at policy refresh; policy settings are enforced and take precedence when settings conflict. See Microsoft’s Group Policy preferences in Windows.

Microsoft explicitly warns against configuring Restricted Groups and LocalUsersAndGroups on the same device because the combination is unsupported and may produce unpredictable results. The version recommendation and policy behavior are documented in Policy CSP – RestrictedGroups and Policy CSP – LocalUsersAndGroups.

Plan a safe Restricted Groups deployment

  1. Confirm the target. Identify the domain-joined workstations or member servers and the local group you intend to manage. Do not use Restricted Groups to define the membership of an AD domain group.
  2. Inspect current membership. Record who currently belongs to the target local group, including accounts or groups added by existing policy or operational processes. Pay particular attention to local Administrators so you do not unintentionally remove an access or support path.
  3. Choose replacement deliberately. If you use the Restricted Groups Members list, include every member that should remain. Any omitted current member is subject to removal when policy is enforced. If your goal is to add or remove selected members while preserving unspecified membership on Windows 10 version 20H2 or later, evaluate LocalUsersAndGroups with its Update action instead.
  4. Configure and scope the policy. In Group Policy Management, edit or create a Group Policy Object (GPO) linked to the organizational unit containing the intended computers. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Restricted Groups, add the local group to restrict, and configure its Members list. Add a domain group as a member only when the intent is for that domain group to belong to the local group.
  5. Test before broad rollout. Apply the GPO to a limited test group of representative computers, then verify the resulting local-group membership and that required administrative access still works. Expand scope only after the result matches the intended membership.

Microsoft’s guidance on securing local administrator accounts and groups is available in Appendix H – Securing Local Administrator Accounts and Groups.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When the device is Microsoft Entra joined

Microsoft documents a separate option for assigning users or Microsoft Entra groups to local Administrators on Microsoft Entra joined devices. Windows sign-in evaluates up to 20 groups, including nested groups, for administrator rights; Microsoft recommends keeping within that limit. This is an adjacent management path for Entra-joined devices, not a reason to apply both Restricted Groups and LocalUsersAndGroups to one device. See How to manage local administrators on Microsoft Entra joined devices.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.