SY0-701 · 4.5 Group Policy 4.6 Least privilege Simulation lab

Lock Down the Local Administrators Group via Group Policy

Northgate Logistics · domain northgate.lan (NetBIOS NORTHGATE)

You are the systems security lead at Northgate Logistics. A recent review of the company's workstations found that, over time, help-desk staff, vendors, and a few users had each been dropped into the local Administrators group on individual machines. That sprawl means far more accounts than necessary hold full control of each endpoint.

You will use a Group Policy Preferences → Local Users and Groups item, inside a dedicated GPO linked at the domain, to force every workstation's built-in Administrators group to a known, minimal membership.

Your task — configure the Local Group preference item so that it:

  1. Targets the built-in Administrators group using the Update action.
  2. Removes every existing member user (Delete all member users).
  3. Removes every existing member group (Delete all member groups).
  4. Adds the built-in local Administrator account as the only retained local member.
  5. Adds NORTHGATE\Domain Admins so domain administrators keep access.

Open the Local Users and Groups node in the tree, choose New → Local Group, and fill in the dialog. The checklist on the right updates itself as you go.

Group Policy Management Editor — Workstation Local Admin Lockdown [DC01.northgate.lan]
No preference items yet. Choose New → Local Group to create one.

Task checklist

Auto-checks as you configure the preference item.

    Knowledge check

    Answer all three. Selections are checked immediately.

    Current score 0 / 8

    Submit completed lab

    Use a hacker name (pseudonym) — do not enter your real name.

    Pseudonym only. Your instructor maps it to you on a separate roster.

    Originality & integrity: this lab is an original clean-room work for SY0-701 objective coverage. The checklist and score are computed in the browser (self-reported); for graded use the Apps Script can re-score answers server-side. © 2026 [Author]. All rights reserved.