I am trying to filter a workstyle to only the built-in local admin.
I dont think wildcards can be used in the SID field and using just the username is not super reliable.. but seems to be the only option...
Anyone done this and have any tips?
Best answer by Jens Hansen
Hi Akel.
If you are using just a local account, it should be able to match with just the account name and no SID. similar to the filtering that is used for the old IC3 Adapter, which specifically target a local account. see the XML MMC and WPE.
policy XML viewWPE Policy editorGood old missed MMC editor. still the best.
When you add local accounts, no SIDs are added and are automatically added as “Local Account”
You can replace the name with any other name. if you have renamed the original administrator.
If you are using just a local account, it should be able to match with just the account name and no SID. similar to the filtering that is used for the old IC3 Adapter, which specifically target a local account. see the XML MMC and WPE.
policy XML viewWPE Policy editorGood old missed MMC editor. still the best.
When you add local accounts, no SIDs are added and are automatically added as “Local Account”
You can replace the name with any other name. if you have renamed the original administrator.
Thank you yeah it works that way as expected. I found to be on the safe side renamingthe account to a known name via GPO is effective to ensure they match.
Appreciate your time :)
Badge Earners
AdrianRhas earned the badge 1 Courses Completed - Entitle
Vercruysse Stevenhas earned the badge BCIE: Privileged Remote Access