Add admins when the Administrators group is empty

Problem

The administrators group on Windows is deleted, leaving the device without admin account. 

Environment

  • Windows
  • Google Credential Provider for Windows

Solution

  1. Log in to the Admin console.
  2. Navigate to Devices Mobile and endpoints Settings Windows Settings.
  3. Click on Administrative privileges.
  4. If the feature is enabled, go to the section Accounts with local administrative access.
  5. Add the users to the list, you must enter the accounts for the local Administrator group, separated by commas.
  6. Enter Active Directory users as YourDomain\user, Active Directory groups as YourDomain\group and local users as username 
  7. Save the changes.

Cause

When the policy is not properly configured it will clear the administrators group on the device.