Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


net localgroup command not working

Posted on 2004-10-27
Medium Priority
Last Modified: 2013-02-05

We've got a large AD split into regional OU's - I want to add a net localgroup command into the login scripts of our users to ensure that one of our groups is in the local administrators group.

Now.. for example, the domain is called domain.company.com - and the security group object is in AD under domain.company.com/London/Building2/Groups/LON-Building2 Administrators

I've tried a series of commands but seemingly to no avail - any ideas people?

Thanks a lot, 500pnts for this.
Question by:davels
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 85

Expert Comment

ID: 12422133
For the "net localgroup" command, you have to use the pre-Windows 2000 group name; if this contains spaces, you need to enclose it in quotation marks.
net localgroup Administrators "YourDomainName\Your Domain Group" /add
should work. That is, if you use it in a GPO startup script for the machine. In a user logon script, this will only work if the user logging on already has local administrator privileges.

Accepted Solution

abu_deep earned 2000 total points
ID: 12422579
The former global groups net localgroup should have a length less than 20 characters so make your self pretty sure that you've never break the 20 characters limit . Windows NT4 had a length restriction of 20 characters, and that still lingers on in some commands. For this to work using "net local group", use the NT4 compatible group name (you'll find it in ADUC in the properties of the group)

Also  Windows 2000 Server have the same issue with the 20 characters .

Taking in account that it works ok when you add global group to local group with "lusrmgr.msc" kind of Bug on net localgroup

Expert Comment

ID: 38857410
You’ll notice that if you use a “net localgroup administrators /add DOMAIN\Group” that the command fails with a syntax error.  Some folks say that this is because of a limitation on the length of the group name, but I call shenanigans on that explanation.  At any rate, you’ll slam your head against your desk for a while, until you do the following:

1) Open up Notepad

2) Paste in the following lines, substituting [DOMAINNAME] and [DOMAINGROUPNAME] as necessary:

Set objLocalGroup = GetObject("WinNT://./Administrators")



Set objLocalGroup = Nothing

Set objADGroup = Nothing

3) Go to File > Save As, and save it on your Desktop as “script.vbs”

4) Go to Start and type in cmd, then right-click on cmd and choose “Run as Administrator”:

5) CD to your Desktop and then run the command: “cscript script.vbs” as in the example below, and once the script runs, do a “net localgroup administrators” to verify that the script added the requested group properly:

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Enterprise networks where VoIP phones have been deployed frequently use port configurations that allow both a computer and an IP phone to be plugged into the same switch port but use different VLANs. On Cisco equipment I'm referring to the "native V…
We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question