Skip to content

Repository files navigation

sccm-localadmins-ci

ECM (ConfigMgr) Configuration Item/Baseline for Detecting Non-Standard Local Administrators

This Configuration Item (CI) is written in PowerShell. It loops through "Local Adminstrators" group to find any user account added to this group besides standard "Administrator". Code is written with localized versions of Windows in mind. This CI can be added to dedicated Configuration Baseline (CB) or be a part of bigger CB.

LocalAdminsCI.ps - PowerShell code used in CI

FYV Check for Non-Standard Local Administrators CI.cab - Exported CI, can be imported directly to SCCM

FYV Check for Non-Standard Local Administrators CB.cab - Exported CB, can be imported directly to SCCM

Note to localized version of Windows. Get-LocalGroupMember cmdlet returns localized description of group memebers. For example, for Russian version of Windows it returns "Пользователь" instead of "User". Code already handles English and Russian version of Windows, but if you are using something different, you can either replace "Пользователь" to your localized version or add another ObjectClass check.

About

ECM (ConfigMgr) Configuration Item/Baseline for Detecting Non-Standard Local Administrators

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages