Remove-LocalGroupMember

Removes members from a local group.

Syntax

Remove-LocalGroupMember
      [-Group] <LocalGroup>
      [-Member] <LocalPrincipal[]>
      [-WhatIf]
      [-Confirm]
      [<CommonParameters>]
Remove-LocalGroupMember
      [-Member] <LocalPrincipal[]>
      [-Name] <String>
      [-WhatIf]
      [-Confirm]
      [<CommonParameters>]
Remove-LocalGroupMember
      [-Member] <LocalPrincipal[]>
      [-SID] <SecurityIdentifier>
      [-WhatIf]
      [-Confirm]
      [<CommonParameters>]

Description

The Remove-LocalGroupMember cmdlet removes users or groups from a local group.

Note

The Microsoft.PowerShell.LocalAccounts module is not available in 32-bit PowerShell on a 64-bit system.

Examples

Example 1: Remove members from the Administrators group

$members = "Admin02", "MicrosoftAccount\username@Outlook.com", "AzureAD\DavidChew@contoso.com", "CONTOSO\Domain Admins"
Remove-LocalGroupMember -Group "Administrators" -Member $members

This command removes several members from the local Administrators group. The members that this cmdlet removes include a local user account, a Microsoft account, a Microsoft Entra account, and a domain group. This example uses a placeholder value for the user name of an account at Outlook.com.

Parameters

-Confirm

Prompts you for confirmation before running the cmdlet.

Type:SwitchParameter
Aliases:cf
Position:Named
Default value:False
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-Group

Specifies the security group from which this cmdlet removes members.

Type:Microsoft.PowerShell.Commands.LocalGroup
Position:0
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-Member

Specifies an array of users or groups that this cmdlet removes from a security group. You can specify users or groups by name, security ID (SID), or LocalPrincipal objects. Specify SID strings in S-R-I-S-S . . . format.

Type:Microsoft.PowerShell.Commands.LocalPrincipal[]
Position:1
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-Name

Specifies the name of the security group from which this cmdlet removes members.

Type:String
Position:0
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-SID

Specifies the security ID of the security group from which this cmdlet removes members.

Type:SecurityIdentifier
Position:0
Default value:None
Required:True
Accept pipeline input:False
Accept wildcard characters:False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type:SwitchParameter
Aliases:wi
Position:Named
Default value:False
Required:False
Accept pipeline input:False
Accept wildcard characters:False

Inputs

System.Management.Automation.SecurityAccountsManager.LocalPrincipal

You can pipe a local principal to this cmdlet.

String

You can pipe a string to this cmdlet.

SecurityIdentifier

You can pipe a SID to this cmdlet.

Outputs

None

This cmdlet returns no output.

Notes

Windows PowerShell includes the following aliases for Remove-LocalGroupMember:

  • rlgm

The PrincipalSource property is a property on LocalUser, LocalGroup, and LocalPrincipal objects that describes the source of the object. The possible sources are as follows:

  • Local
  • Active Directory
  • Microsoft Entra group
  • Microsoft Account

PrincipalSource is supported only by Windows 10, Windows Server 2016, and later versions of the Windows operating system. For earlier versions, the property is blank.