I know that one can use "Restricted Groups" for that purpose, but this will also mean that any members inside the local "Administrators" Group will be deleted and I don't want that to happen.
There's no direct way to do this with Group Policy, as you rightly say the "Restricted Groups" is a wipe-and-replace operation, not incremental.
One way would be to use a script to do it, although that would need to run in a context with sufficient permissions, so either using an existing user account that already has local admin rights, or as a machine startup script. The relevant command to go into a script would be:
net localgroup administrators <YourDomain><SomeGroup> /add
This was first published in September 2006
Join the conversationComment
Share
Comments
Results
Contribute to the conversation