Adding or removing members on FSLogix local groups using Restricted Groups

Published Apr 23 2021 09:43 AM 2,974 Views
Microsoft

Hello Folks! @Guido here.

 

This is my very first blog and I'd like to share with you how we can add or remove members from FSLogix local groups using a GPO.

 

To recap

 

There are often users, such as local administrators, that have profiles that should remain local. During installation, four user groups are created to manage users who's profiles are included and excluded from Profile Container and Office Container redirection.

 

FSLogix include or Exclude groups allow us to add or exclude members from FSLogix service so the users can get the default local profile instead using a FSLogix container.

 

restricted_group.png

 

 

 

  

  • By default Everyone is added to the FSLogix Profile Include List group.
  • Adding a user to the FSLogix Profile Exclude List group means that the FSLogix agent will not attach a FSLogix profile container for the user.
  • FSLogix Profile Exclude List group take priority over FSLogix Profile Exclude List group if there is a member on both Local Groups.

 

Adding or removing member of a Local Groups is extremely easy on a few machines but what happens if you have deployed hundred or thousands of machines? Here where Restricted Groups comes into play.

 
Restricted Groups

Restricted groups allow an administrator to define the following two properties for security-sensitive (restricted) groups:

 

Using the "Members" Restricted Group Portion of Policy
When a Restricted Group policy is enforced, any current member of a restricted group that is not on the "Members" list is removed with the exception of administrator in the Administrators group. Any user on the "Members" list which is not currently a member of the restricted group is added.

Using the "Member Of" Restricted Group Portion of Policy
Only inclusion is enforced in this portion of a Restricted Group policy. The Restricted Group is not removed from other groups. It makes sure that the restricted group is a member of groups that are listed in the Member Of dialog box.

 

Let's start

 

  1. Open Group Policy Management Console
  2. Create a new GPO or edit an existing one.
  3. Go to Computer Configuration --> Policies --->Windows Settings-->Security Settings-->Restricted Groups
  4. Right click over Restricted Group and select Add Group
  5. Type the Group you you want to add or remove members. The name must match with the local one. I recommend you to just copy and paste the name to avoid mistakes.

 

guido_screen2.png

 

Then add the members in Members of this group

 

guido_screen3.png

 

Note: Adding members in Members of this Group option will be deleting other local members if they already exist. If you want to keep the existing members, just add the members under This group is member of option

 

You can validate it from client machine local group side.

 

 

guido_screen4.png

 

Hope you find this useful and informative.

 

Keep in touch.

Guido.

%3CLINGO-SUB%20id%3D%22lingo-sub-2278484%22%20slang%3D%22en-US%22%3EAdding%20or%20removing%20members%20on%20FSLogix%20local%20groups%20using%20Restricted%20Groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2278484%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Folks!%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F400659%22%20target%3D%22_blank%22%3E%40Guido%3C%2FA%3E%26nbsp%3Bhere.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20is%20my%20very%20first%20blog%20and%20I'd%20like%20to%20share%20with%20you%20how%20we%20can%20add%20or%20remove%20members%20from%20FSLogix%20local%20groups%20using%20a%20GPO.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ETo%20recap%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20are%20often%20users%2C%20such%20as%20local%20administrators%2C%20that%20have%20profiles%20that%20should%20remain%20local.%20During%20installation%2C%20four%20user%20groups%20are%20created%20to%20manage%20users%20who's%20profiles%20are%20included%20and%20excluded%20from%20Profile%20Container%20and%20Office%20Container%20redirection.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFSLogix%20include%20or%20Exclude%20groups%20allow%20us%20to%20add%20or%20exclude%20members%20from%20FSLogix%20service%20so%20the%20users%20can%20get%20the%20default%20local%20profile%20instead%20using%20a%20FSLogix%20container.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22restricted_group.png%22%20style%3D%22width%3A%20690px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F273919iFCE961CBC934A811%2Fimage-dimensions%2F690x448%3Fv%3Dv2%22%20width%3D%22690%22%20height%3D%22448%22%20role%3D%22button%22%20title%3D%22restricted_group.png%22%20alt%3D%22restricted_group.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EBy%20default%20Everyone%20is%20added%20to%20the%20FSLogix%20Profile%20Include%20List%20group.%3C%2FLI%3E%0A%3CLI%3EAdding%20a%20user%20to%20the%20FSLogix%20Profile%20Exclude%20List%20group%20means%20that%20the%20FSLogix%20agent%20will%20not%20attach%20a%20FSLogix%20profile%20container%20for%20the%20user.%3C%2FLI%3E%0A%3CLI%3EFSLogix%20Profile%20Exclude%20List%20group%20take%20priority%20over%20FSLogix%20Profile%20Exclude%20List%20group%20if%20there%20is%20a%20member%20on%20both%20Local%20Groups.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAdding%20or%20removing%20member%20of%20a%20Local%20Groups%20is%20extremely%20easy%20on%20a%20few%20machines%20but%20what%20happens%20if%20you%20have%20deployed%20hundred%20or%20thousands%20of%20machines%3F%20Here%20where%20Restricted%20Groups%20comes%20into%20play.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CBR%20%2F%3E%3CSTRONG%3ERestricted%20Groups%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3ERestricted%20groups%20allow%20an%20administrator%20to%20define%20the%20following%20two%20properties%20for%20security-sensitive%20(restricted)%20groups%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EUsing%20the%20%22Members%22%20Restricted%20Group%20Portion%20of%20Policy%3C%2FSTRONG%3E%3CBR%20%2F%3EWhen%20a%20Restricted%20Group%20policy%20is%20enforced%2C%20any%20current%20member%20of%20a%20restricted%20group%20that%20is%20not%20on%20the%20%22Members%22%20list%20is%20removed%20with%20the%20exception%20of%20administrator%20in%20the%20Administrators%20group.%20Any%20user%20on%20the%20%22Members%22%20list%20which%20is%20not%20currently%20a%20member%20of%20the%20restricted%20group%20is%20added.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSTRONG%3EUsing%20the%20%22Member%20Of%22%20Restricted%20Group%20Portion%20of%20Policy%3C%2FSTRONG%3E%3CBR%20%2F%3EOnly%20inclusion%20is%20enforced%20in%20this%20portion%20of%20a%20Restricted%20Group%20policy.%20The%20Restricted%20Group%20is%20not%20removed%20from%20other%20groups.%20It%20makes%20sure%20that%20the%20restricted%20group%20is%20a%20member%20of%20groups%20that%20are%20listed%20in%20the%26nbsp%3BMember%20Of%26nbsp%3Bdialog%20box.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ELet's%20start%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EOpen%20Group%20Policy%20Management%20Console%3C%2FLI%3E%0A%3CLI%3ECreate%20a%20new%20GPO%20or%20edit%20an%20existing%20one.%3C%2FLI%3E%0A%3CLI%3EGo%20to%20Computer%20Configuration%20--%26gt%3B%20Policies%20---%26gt%3BWindows%20Settings--%26gt%3BSecurity%20Settings--%26gt%3BRestricted%20Groups%3C%2FLI%3E%0A%3CLI%3ERight%20click%20over%20Restricted%20Group%20and%20select%20Add%20Group%3C%2FLI%3E%0A%3CLI%3EType%20the%20Group%20you%20you%20want%20to%20add%20or%20remove%20members.%20The%20name%20must%20match%20with%20the%20local%20one.%20I%20recommend%20you%20to%20just%20copy%20and%20paste%20the%20name%20to%20avoid%20mistakes.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22guido_screen2.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F273914i72DD50532F535C47%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22guido_screen2.png%22%20alt%3D%22guido_screen2.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThen%20add%20the%20members%20in%20Members%20of%20this%20group%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22guido_screen3.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F273912i0724969B69C3CA8C%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22guido_screen3.png%22%20alt%3D%22guido_screen3.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENote%3A%20Adding%20members%20in%20%3CSTRONG%3E%3CEM%3EMembers%20of%20this%20Group%3C%2FEM%3E%3C%2FSTRONG%3E%20option%20will%20be%20deleting%20other%20local%20members%20if%20they%20already%20exist.%20If%20you%20want%20to%20keep%20the%20existing%20members%2C%20just%20add%20the%20members%20under%20%3CSTRONG%3E%3CEM%3EThis%20group%20is%20member%20of%3C%2FEM%3E%3C%2FSTRONG%3E%20option%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20validate%20it%20from%20client%20machine%20local%20group%20side.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22guido_screen4.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F273913iD8EE9DD107B3CC79%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22guido_screen4.png%22%20alt%3D%22guido_screen4.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20you%20find%20this%20useful%20and%20informative.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EKeep%20in%20touch.%3C%2FP%3E%0A%3CP%3EGuido.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2278484%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20you%20ever%20wondered%20how%20to%20manage%20FSLogix%20groups%20using%20Group%20Policies%3F%20Here%20we%20will%20talk%20about%20it.%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Version history
Last update:
‎Apr 19 2021 02:56 PM
Updated by:
www.000webhost.com