Domain Controller Builtin\Administrators (Restricted Groups)

Anonymous
2021-09-19T15:22:56.75+00:00

When working with Active Directory, does anyone know why Restricted Groups within Group Policy cannot be used to add a group to the Builtin\Administrators group on a domain controller?

I am able to use Restricted Groups to replace all the groups and add the ones I want but I cannot use it to add a group to Builtin\Administrators on the domain controller.

No other policies are overwriting this.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,789 questions
0 comments No comments
{count} votes

Accepted answer
  1. cthivierge 4,056 Reputation points
    2021-09-20T16:36:22.8+00:00

    Both are working well

    133628-group5.png

    133674-group6.png

    1 person found this answer helpful.

3 additional answers

Sort by: Most helpful
  1. Limitless Technology 39,391 Reputation points
    2021-09-20T14:21:54.28+00:00

    Hello,

    When a restricted group policy is enforced, any current member of a restricted group that isn't on the Members list is removed, except for the administrator in the Administrators group. Any user on the Members list that isn't currently a member of the restricted group is added.

    Only inclusion is enforced in this portion of a restricted group policy. The restricted group isn't removed from other groups. It makes sure that the restricted group is a member of groups that are listed in the Member Of dialog box.

    While Builtin\Administrators denotes the Administrators of Local Group, on machine server.

    Do follow the below link to get to know further

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/description-of-group-policy-restricted-groups

    Hope this answers all your queries, if not please do repost back.
    If an Answer is helpful, please click "Accept Answer" and upvote it : )

    0 comments No comments

  2. cthivierge 4,056 Reputation points
    2021-09-20T14:37:08.057+00:00

    I think it should work. It's working in my lab environment.

    Here's my GPO and where it's linked

    133635-group1.png

    133636-group2.png

    133665-group3.png

    133569-group4.png


  3. Limitless Technology 39,391 Reputation points
    2021-09-20T17:59:46.65+00:00

    Hello @Anonymous

    Additionally,

    This is because once you promote a computer to Domain Controller, all the local security groups are "migrated" to domain groups, and the local Administrators group is removed. This is due to the local SAM database usage, but there is a very good explanation in this post:

    https://social.technet.microsoft.com/Forums/exchange/en-US/91294fdf-1565-4861-bf23-ba62937f1c11/what-happens-to-local-users-and-groups-after-a-computer-joined-a-domain?forum=winservergen

    Best regards,

    0 comments No comments