Skip to content

$cs.UsrMgr_AddUserToLocalGroup

Adds a local user account to a local group. The groupName parameter accepts either a plain group name (e.g. Administrators) or a group SID.

The function doesn’t throw an exception when Windows can’t add the member — for example, because the user doesn’t exist or is already a member of the group. The job log still says the user was added. To confirm the result, check the group with $cs.UsrMgr_EnumMembersOfLocalGroup.

$cs.UsrMgr_AddUserToLocalGroup(string userName, string groupName)

The account to add to the group: a local user name, or a domain account in DOMAIN\username format. Names that contain spaces aren’t supported.

The group to add the user to. Can be a plain group name or a SID (a value containing S-1-5- is treated as a SID). Group names that contain spaces, such as Remote Desktop Users, aren’t supported — use the group’s SID instead (for Remote Desktop Users, S-1-5-32-555).

None.

Add a service account to the local Administrators group by name during install:

Terminal window
if ($cs.UsrMgr_ExistLocalUserAccount('capaadmin')) {
$cs.Job_WriteLog("Adding capaadmin to Administrators group")
$cs.UsrMgr_AddUserToLocalGroup('capaadmin', 'Administrators')
}

Use the well-known SID S-1-5-32-544 instead of the localized group name, so the same script works on non-English builds of Windows:

Terminal window
if ($cs.UsrMgr_ExistLocalUserAccount('svc_capaagent')) {
$cs.Job_WriteLog("Adding svc_capaagent to the local Administrators group (locale-independent)")
$cs.UsrMgr_AddUserToLocalGroup('svc_capaagent', 'S-1-5-32-544')
}

Grant a support account access to a custom, application-specific local group:

Terminal window
if ($cs.UsrMgr_ExistLocalUserAccount('capasupport')) {
$cs.Job_WriteLog("Adding capasupport to AppRemoteUsers")
$cs.UsrMgr_AddUserToLocalGroup('capasupport', 'AppRemoteUsers')
}

$cs.UsrMgr_RemoveUserFromLocalGroup $cs.UsrMgr_EnumMembersOfLocalGroup